August 19, 2025 RocketCyber release notes

Syslog MultiLink

Overview

Previously, RocketCyber could designate only one agent as the syslog collector for each organization. This limitation meant that organizations with multiple networks could not effectively monitor all of their firewalls, as only one collector could be utilized. The new feature allows for multiple syslog collectors per organization, enabling the RocketCyber SOC to monitor all firewalls and network devices seamlessly.

Syslog Servers

A new Syslog Servers tab has been added to the Firewall Log Analyzer app configuration menu. This tab allows you to select one or more devices to designate as syslog servers. After selecting the desired devices, click Update to save your changes

NOTE  Only Windows devices will appear in this list, as we do not currently support syslog servers for Mac/Linux.

Configuring the Syslog Servers

The Syslog Configuration tab now supports multiple configurations. Previously, the Syslog Server Device drop-down menu allowed you to select only one device to act as the syslog server. Now, all selected devices will be available in this drop-down menu, with each device functioning as its own syslog server and having a unique configuration. Selecting a device from the drop-down menu will load the syslog server configuration associated with that device.

NOTE  After making changes to a syslog server configuration, be sure to click Update before switching the selected device in the Syslog Server Device drop-down menu; otherwise, you will lose any unsaved changes.

After selecting and configuring all devices, you can point any supported firewall syslog events to these devices. They will then populate under the same organization within the Firewall Log Analyzer app.