Adding ForeScout CounterACT via Syslog

Purpose

This guide explains how to forward ForeScout CounterACT events to Logsign USO over syslog. The integration covers NAC policy evaluations, appliance and plugin log messages, console and directory authentication activity, block and scan events, system statistics and connection notifications. Logsign parses the messages natively and normalizes them under Vendor ForeScout, Product CounterACT.

Prerequisites

  • A CounterACT Console account that is allowed to configure the Syslog plugin.
  • Network connectivity from the CounterACT Appliance and Enterprise Manager to the Logsign USO collector on your syslog port (UDP or TCP 514 by default).
  • The IP address of each CounterACT device that will send logs, so the source can be added in Logsign USO.

Step 1: Configure syslog forwarding on CounterACT

Menu names differ between CounterACT releases. In most versions the Syslog plugin is configured from the CounterACT Console under Tools > Options > Modules > Syslog. If the path does not match your console, check the ForeScout Syslog Plugin documentation for your version.

  1. Open the Syslog plugin configuration and add a new syslog server.
  2. Enter the IP address of the Logsign USO collector, the syslog port and the protocol (UDP or TCP).
  3. Enable the message categories you want to collect. Policy events, event logs and appliance or plugin messages are the ones this integration classifies.
  4. Leave the message format at the plugin default. Both the classic BSD header and the newer RFC5424 header are accepted, so you do not need to change the header style for Logsign.
  5. Apply the configuration and make sure it is assigned to every Appliance that should forward logs, not only to the Enterprise Manager.

Step 2: Add the data source in Logsign USO

Open the Logsign USO web interface and click + Device under Settings > Data Collection. Choose Syslog as the collection method, select ForeScout as the vendor and CounterACT as the product, and enter the IP address of the CounterACT device as the host. Click Save. Repeat this for every Appliance that forwards logs. Once the plugin starts sending, events appear under Search.

Supported message formats

Logsign accepts CounterACT messages with either syslog header style, and it also accepts CEF output from CounterACT.

A message with the classic BSD header looks like this (anonymized):

<14>Sep 17 08:32:39 nacappliance CounterACT[2298]: NAC Policy Log: Source: 10.0.0.22, Rule: Policy "0.1 Test New Host" , Match: "0.1 Test New Host:Unmatched", Category: N/A, Details: Host evaluation changed from "0.1 Test New Host:Match" to "0.1 Test New Host:Unmatched" due to condition . Reason: Admission expired. Duration: 10 minutes and 1 second

The same event with an RFC5424 header looks like this:

<14>1 2026-09-17T08:32:39.000000Z nacappliance CounterACT - - - NAC Policy Log: Source: 10.0.0.22, Rule: Policy "0.1 Test New Host" , Match: "0.1 Test New Host:Unmatched", Category: N/A, Details: Host evaluation changed from "0.1 Test New Host:Match" to "0.1 Test New Host:Unmatched" due to condition . Reason: Admission expired. Duration: 10 minutes and 1 second

In the RFC5424 form the version field must be 1, the timestamp must carry a Z suffix or a numeric offset, and the process ID, message ID and structured data fields must all be present, either with a value, as a single -, or as a bracketed structured data block. This matches what the CounterACT Syslog plugin produces. Plain text messages that arrive without a recognizable syslog header are not parsed by this integration.

CEF messages are recognized as soon as the body starts with CEF:<version>|. The CEF body can arrive on its own, behind a syslog tag such as CounterACT[2477315]: or CounterACT_CEF[1672]:, behind a BSD header with that tag, or behind an RFC5424 header. A CEF compliance event with a BSD header looks like this (anonymized):

<14>Sep 24 10:08:08 nacappliance CounterACT[2477315]: CEF:0|ForeScout Technologies|CounterAct|9.1.2|COMPLIANCE|host is compliant|1|cs1Label=Compliancy Policy Name cs2Label=Compliancy Policy Subrule Name cs3Label=Host Compliancy Status cs4Label=Compliancy Event Trigger cs1=1.2 DLP Agent Check cs2=DLP Agent Not Installed cs3=yes cs4=CounterAct Action dmac=00:50:56:aa:bb:cc dst=10.10.20.30 dntdom=EXAMPLE dhost=workstation01 duser=user dvc=10.10.1.5 dvchost=nacappliance rt=1790232488000

Recognition of CEF messages that carry the CounterACT[pid]: tag or a full syslog header in front of the CEF body is available from Logsign USO 6.4.121. On earlier versions only a bare CEF body or the CounterACT_CEF[pid]: tag is recognized, and other CEF messages end up as Uncategorized Event with the whole body in Event.Note.

What gets collected

Logsign fieldCounterACT value
Time.GeneratedThe timestamp in the syslog header, from either the BSD or the RFC5424 form. For CEF messages the rt field is used instead of the syslog header, in epoch milliseconds or epoch seconds. If rt is not an epoch value, the time the message was processed is used.
Event.TypeThe message type, for example NAC Policy Log, Log, Block Event, System statistics, Application status, Scan event or Port bite
Event.InfoThe message subject, for example User Directory Connect Successful or Connection has been established
Event.ActionThe policy match result taken from the part of Match after the last colon, for example Match, Unmatched, Pending or Irresolvable. For console and directory events it is the action itself, such as Login success, Login failed or Logout.
Event.DetailsDetails
Event.ReasonReason
Event.NoteThe raw message body when it does not match any known message type
Source.IP, Source.City, Source.CountryThe endpoint address reported as Source, or the client address in login and connection messages
Source.UserNameThe user in login, directory and policy messages
Source.MACThe endpoint MAC address when the message carries mac=
Destination.IP, Destination.PortThe target address of scan, port bite and connection messages. The port comes from Service in the port/protocol form.
Protocol.NameThe protocol part of Service
Policy.NameRule
Policy.CategoryCategory
Rule.NameThe part of Match before the last colon, which is the sub rule that produced the result
Severity.Name, Severity.IDAssigned by Logsign from the classification table below, not taken from the CounterACT Severity value
EventSource.PrefixID4087

Other key and value pairs in policy messages, such as Duration, are kept as they arrive. Every event is recorded with Vendor ForeScout, Product CounterACT, EventSource Type Security System and Category NAC.

CEF messages are mapped from their CEF keys. The custom string fields are identified by their labels, so the rows below assume the labels that CounterACT sends for compliance events.

Logsign fieldCEF key
Event.CategorySignature ID, for example COMPLIANCE or NONCOMPLIANCE
Event.InfoName, for example host is compliant
Event.Statuscs3 (Host Compliancy Status), for example yes
Event.Descriptioncs4 (Compliancy Event Trigger), for example CounterAct Action
Policy.Namecs1 (Compliancy Policy Name)
Rule.Namecs2 (Compliancy Policy Subrule Name)
Source.IP, Source.City, Source.Countrydst, the endpoint that was evaluated
Source.MACdmac
Source.HostNamedhost
Source.UserNameduser
Source.Domaindntdom
Device.IPdvc, the CounterACT appliance
Device.HostNamedvchost, the CounterACT appliance
EventSource.VersionDevice version from the CEF header, for example 9.1.2
Time.Generatedrt

Event classification

CounterACT messageEventMapSeverity
NAC Policy LogSystem / Application / Infonotice
Application statusSystem / Application / Infoinformation
System statisticsSystem / State / Infoinformation
LogSystem / Operation / Infonotice
Connection has been establishedSystem / Operation / Infoinformation
Log, Login success or acceptedIdentity / User / Logininformation
Log, LogoutIdentity / User / Logoutinformation
Log, Login failed or rejectedIdentity / User / Denywarning
Block EventSecurity / Attack / Blockwarning
Scan eventSecurity / Scan / Infocritical
Port biteSecurity / Attack / Infocritical
Mail Infection AttemptSecurity / Malware / Infowarning

When CounterACT sends CEF instead, the classification is taken from the CEF signature ID. The COMPLIANCE signature is recorded as Network / Other / Info with severity information, and NONCOMPLIANCE as Network / Other / Error with severity warning.

Notes and limits

  • Time zones are not converted. The timestamp is stored exactly as CounterACT sends it, for both header styles. If the plugin sends UTC and your console shows local time, the events appear shifted by your offset, so send local time if you want the two to line up. CEF messages are different: rt is an epoch value, so it is converted to the local time of the Logsign server.
  • Sub second precision is dropped. A timestamp such as 08:32:39.000000Z is stored with second precision.
  • Long messages that CounterACT splits with a | Part (1/6) | prefix are collected, but the parts are not joined back together. Each part is stored on its own and the message body goes to Event.Note.
  • Policy names arrive with the literal prefix that CounterACT puts in the Rule field, so Policy.Name reads Policy "0.1 Test New Host rather than the bare policy name. Take this into account when you build searches or dashboards on Policy.Name. Rule.Name is not affected.
  • Uptime notices such as Uptime 1234 seconds have no dedicated rule. They are collected, with the text kept in Event.Note.
  • A CEF message behind a syslog header whose CEF header is cut short or otherwise malformed is not dropped. It is collected as a plain message with the body in Event.Note.
  • Messages that do not match any of the classifications above are still collected and searchable, but they show as Uncategorized Event because no EventMap applies to them.

Verification

  • In Logsign USO, open Settings > Data Collection and confirm that the ForeScout CounterACT source is receiving data.
  • Go to Search and look for events with Vendor ForeScout and Product CounterACT. A policy evaluation should appear with Event.Type NAC Policy Log, EventMap System / Application / Info, the endpoint address in Source.IP and the policy result in Event.Action.
  • If CounterACT sends CEF, a compliance event should appear with Event.Category COMPLIANCE, EventMap Network / Other / Info, the policy in Policy.Name and the appliance in Device.IP and Device.HostName.
  • Log in to the CounterACT Console to generate an authentication event. It should appear with EventMap Identity / User / Login and your user name in Source.UserName.
  • If the source is receiving data but the events carry no Vendor value, the messages are not in a format this integration recognizes. Check that the Syslog plugin is left at its default message format and that the syslog header is not stripped or rewritten by a relay on the path.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.