Fabric → Workers → Collector
A worker can run a syslog collector that receives logs inbound from your network devices and servers — firewalls, switches, routers, and Linux/Windows hosts — and ingests them into MisterShell so they become searchable and correlatable. This is the opposite direction from Log Forwarding, which sends MisterShell’s own audit events outbound to a SIEM. Turning a collector on requires the Syslog Collector add-on.
A collector is configured per worker, in the Collector section of the worker’s form on the Fabric Estate tab. What happens to the logs once ingested is decided separately, on Govern → Syslog Policy.
What you can do
- Enable a collector on any worker.
- Restrict which source networks a collector accepts logs from.
- Size the on-disk spool that buffers logs when the link to the core server drops.
Fields
The Collector section is always present on the worker’s create/edit form. Without the Syslog Collector add-on — or once every licensed collector slot is in use — its inputs are locked, with a padlock explaining what is missing; a collector that is already enabled can still be switched off. Each worker with collection switched on consumes one unit of the add-on’s Collector Workers capacity (see Licensing).
| Field | Meaning |
|---|---|
| Enable syslog collector | Turn the collector on or off for this worker. |
| Allowed source CIDRs | An optional allow-list of source IP ranges (in CIDR notation) permitted to send logs. Type a CIDR and press Enter to add it. Leave empty to accept logs from any source. |
| Spool size (MB) | The on-disk buffer that holds received logs if the link to the core server drops, so nothing is lost during a brief outage (64–65536 MB). |
The collector listens on the standard syslog port (514) by default. To bind an unprivileged port instead, set COLLECTOR_LISTEN_PORT (for example, 1514) in the worker’s configuration on its host — the listening port is a host-side setting, not a field on this form.
Common tasks
Enable the collector on a worker
- On the Fabric Estate tab, filter to Workers and Edit the worker you want to run the collector.
- In the Collector section, turn Enable syslog collector on.
- Optionally set Allowed source CIDRs and the Spool size.
- Click Update.
Restrict which sources are accepted
- Edit the worker.
- In Allowed source CIDRs, add the source IP ranges you expect logs from (for example, your management subnet).
- Click Update. Logs from addresses outside the list are refused. Leave the field empty to accept all sources.
Point a device at the collector
Aim the device’s syslog output at the worker’s host on the collector’s listening port, over UDP or TCP.
- On a Cisco device, set
logging <worker-host>(and the matching transport/port). - On a Linux host with rsyslog, add a forwarding rule such as
*.* @@worker-host:port(@@for TCP,@for UDP). - On a Windows host, point your syslog agent at the same host and port.
- Save and apply the device’s logging configuration.
Verify ingestion
Open Review → Syslog and confirm the new records appear in the viewer.
Permissions
- View collector policy:
app.collector.read. - View ingested logs in allowed location branches:
app.collector.execute. - Enable and configure a worker’s collector:
app.fabric.write.