Skip to content
User Guide

Fabric → Workers → Collector

A worker can run a syslog collector that receives logs inbound from your network devices and servers — firewalls, switches, routers, and Linux/Windows hosts — and ingests them into MisterShell so they become searchable and correlatable. This is the opposite direction from Log Forwarding, which sends MisterShell’s own audit events outbound to a SIEM. Turning a collector on requires the Syslog Collector add-on.

A collector is configured per worker, in the Collector section of the worker’s form on the Fabric Estate tab. What happens to the logs once ingested is decided separately, on Govern → Syslog Policy.

What you can do

  • Enable a collector on any worker.
  • Restrict which source networks a collector accepts logs from.
  • Size the on-disk spool that buffers logs when the link to the core server drops.

Fields

The Collector section is always present on the worker’s create/edit form. Without the Syslog Collector add-on — or once every licensed collector slot is in use — its inputs are locked, with a padlock explaining what is missing; a collector that is already enabled can still be switched off. Each worker with collection switched on consumes one unit of the add-on’s Collector Workers capacity (see Licensing).

FieldMeaning
Enable syslog collectorTurn the collector on or off for this worker.
Allowed source CIDRsAn optional allow-list of source IP ranges (in CIDR notation) permitted to send logs. Type a CIDR and press Enter to add it. Leave empty to accept logs from any source.
Spool size (MB)The on-disk buffer that holds received logs if the link to the core server drops, so nothing is lost during a brief outage (64–65536 MB).

The collector listens on the standard syslog port (514) by default. To bind an unprivileged port instead, set COLLECTOR_LISTEN_PORT (for example, 1514) in the worker’s configuration on its host — the listening port is a host-side setting, not a field on this form.

Common tasks

Enable the collector on a worker

  1. On the Fabric Estate tab, filter to Workers and Edit the worker you want to run the collector.
  2. In the Collector section, turn Enable syslog collector on.
  3. Optionally set Allowed source CIDRs and the Spool size.
  4. Click Update.

Restrict which sources are accepted

  1. Edit the worker.
  2. In Allowed source CIDRs, add the source IP ranges you expect logs from (for example, your management subnet).
  3. Click Update. Logs from addresses outside the list are refused. Leave the field empty to accept all sources.

Point a device at the collector

Aim the device’s syslog output at the worker’s host on the collector’s listening port, over UDP or TCP.

  1. On a Cisco device, set logging <worker-host> (and the matching transport/port).
  2. On a Linux host with rsyslog, add a forwarding rule such as *.* @@worker-host:port (@@ for TCP, @ for UDP).
  3. On a Windows host, point your syslog agent at the same host and port.
  4. Save and apply the device’s logging configuration.

Verify ingestion

Open Review → Syslog and confirm the new records appear in the viewer.

Permissions

  • View collector policy: app.collector.read.
  • View ingested logs in allowed location branches: app.collector.execute.
  • Enable and configure a worker’s collector: app.fabric.write.