Lenovo XClarity Controller Integration via Syslog

Purpose

This guide explains how to forward Lenovo XClarity Controller (XCC) event logs to Logsign USO via syslog for security analytics and forensic purposes. XClarity Controller is the baseboard management controller (BMC) built into Lenovo ThinkSystem/ThinkServer hardware, and its event log covers hardware health, power, and out-of-band management events (login attempts, configuration changes, sensor alerts, and similar).

Prerequisites

  • Administrator access to the XClarity Controller web interface for each server.
  • Network connectivity from the XClarity Controller's management network to Logsign USO over syslog (UDP/TCP 514, or your organization's standard syslog port).

Step 1: Configure Remote Syslog on XClarity Controller

The steps below reflect XClarity Controller's general remote-syslog capability. Confirm the exact menu path against your XCC firmware version before publishing, as Lenovo has moved this setting across a few different screens across firmware generations.

  1. Log in to the XClarity Controller web interface.
  2. Navigate to the network/syslog collection settings (typically under BMC Configuration > Network or Security > Syslog, depending on firmware version).
  3. Enable remote syslog forwarding and enter the Logsign USO collector's IP address or hostname and port.
  4. Save the configuration.

Step 2: Add the Data Source in Logsign USO

  1. Add a new syslog source in Logsign USO for the XClarity Controller's management IP.
  2. Set the device/plugin type to Lenovo XClarity Controller.

What Gets Collected

Logsign normalizes XClarity Controller events into its standard schema, including event category, event ID, generated time, the device name/ID/tag of the reporting BMC, the source username and IP (with city/country geo enrichment) for login and administrative events, and severity.

Notes and Limits

  • This covers XClarity Controller's own event log (hardware/BMC-level events), not OS-level logs from the server's operating system. OS logs need a separate collection method (agent, WEF, or syslog from the OS itself).
  • If events stop arriving, check the syslog forwarding configuration on the XCC side first. This is a common point where firmware upgrades reset or relocate this setting.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.