---
title: "Fortanix DSM with Sumo Logic (SIEM) for Linux Server"
slug: "fortanix-dsm-with-sumo-logic-siem-integration-guide-for-linux-server"
updated: 2026-07-27T17:18:15Z
published: 2026-07-27T17:18:15Z
canonical: "support.fortanix.com/fortanix-dsm-with-sumo-logic-siem-integration-guide-for-linux-server"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix DSM with Sumo Logic (SIEM) for Linux Server

## 1.0 Introduction

This article describes how to integrate **Fortanix-Data-Security-Manager (DSM)** with **Sumo Logic (SIEM)** on a Linux Server.

## 2.0 Terminology

- **DSM** – **Data Security Manager**

Data Security Manager is a cloud solution secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as secrets, such as passwords, API keys, tokens, or any blob of data.
- **Sumo Logic**

Sumo Logic is a security information and event management (SIEM) solution that provides security analysts with enhanced visibility across the enterprise to thoroughly understand the impact and context of an attack. Sumo Logic offers streamlined workflows that automatically triage alerts to maximize security analyst efficiency and focus.

## 3.0 Download and Install Sumo Logic Collector in Linux

### 3.1 System Requirements

System requirements for Linux:

- Linux, major distributions 64-bit, or any generic Unix capable of running Java 1.8
- Single core, 512MB RAM
- 8GB disk space
- Package installers require TLS 1.2 or higher

### 3.2 Downloading the Collector

Download the collector in one of the following ways:

- Through the user interface (UI):
  - In Sumo Logic, select **Manage Data** → **Collection** → **Collection**.
  - Click **Add Collector** → **Installed Collector**.
  - Click the link for the collector to begin the download.
- Through a Web Browser:
  - Open a browser and enter the static URL for your pod.
  - The collector begins to download.
  - *Refer to* [*Download a Collector from a Static URL*](https://help.sumologic.com/03Send-Data/Installed-Collectors/05Reference-Information-for-Collector-Installation/02Download-a-Collector-from-a-Static-URL) *for a list of URLs for your deployment pod.*

Fortanix recommends using the collector manually by downloading the `.sh` installation file corresponding to your endpoint. *Refer to* [*https://collectors.in.sumologic.com/rest/download/linux/64*](https://collectors.in.sumologic.com/rest/download/linux/64) *to download the collector for Linux 64-bit.*

Run the following command:

```bash
ubuntu@sumologictest:~$ sudo wget https://collectors.in.sumologic.com/rest/download/linux/64
--2022-05-11 05:22:09-- https://collectors.in.sumologic.com/rest/download/linux/64
Resolving collectors.in.sumologic.com (collectors.in.sumologic.com)... 13.126.102.227, 65.2.26.137, 65.1.116.61, ...
Connecting to collectors.in.sumologic.com (collectors.in.sumologic.com)|13.126.102.227|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 84905788 (81M) [application/octet-stream]
Saving to: '64.1'

64.1                               100%[=======================================================================>]  80.97M  93.5MB/s    in 0.9s

2022-05-11 05:22:11 (93.5 MB/s) - '64.1' saved [84905788/84905788]
```

![Downloading_the_Connector_on_Linux_64_bit_Server.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/6390624360852.png)

**Figure 1: Downloading the connector on Linux 64 bit server**

### 3.3 Generating Access Keys

Perform the following steps to generate access keys:

1. On the UI, click **Profile** → **Preferences** → **Add Access Key**.

![Add_Access_Key.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/6398411490964.png)

**Figure 2: Add access key**
2. Enter a name for the key and click **Create Key**.

![Create_Access_Key.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/6398414075156.png)

**Figure 3: Create access key**

*For more information, refer to* [*Access Keys*](https://help.sumologic.com/Manage/Security/Access-Keys)*.*

### 3.4 Installing the Collector

You can choose one of the following methods to install the Collector:

- [*UI Installer*](https://www.sdkms.fortanix.com#Install_using_the_UI_installer)*:* `https://www.sdkms.fortanix.com/#Install_using_the_UI_installer` (This method does not support all advanced settings)
- [*Command line installer*](https://collectors.in.sumologic.com/rest/download/linux/64#Install_using_the_command_line_installer)
- [*RPM/Debian package*](https://help.sumologic.com/03Send-Data/Installed-Collectors/04Install-a-Collector-on-Linux#Install_using_the_RPM_or_Debian_package)
- [*Binary package*](https://help.sumologic.com/Manage/Security/Access-Keys#Install_using_the_binary_package)

The easiest and fastest way to install the connector is by using the command displayed below and replacing the values of `accesskey` and `accessid`.

```bash
ubuntu@sumologictest:~$ sudo ./SumoCollector.sh -q -Vsumo.accessid=suVzuyDcEwXy6u -Vsumo.accesskey=Kjpta1Obvs5SZMSYoyxYrAKNBTTtrgtPdSTLNXRyRZYS4zyzGcwZaBOauyQfmbih 
Unpacking JRE ...
Starting Installer ...
2022-05-11 05:25:14,118 main WARN The bufferSize is set to 8192 but bufferedIo is false: false
Uninstalling previous version
Extracting files...
Finishing installation...
```

*For more information more about installing a collector on Linux, refer to the* [*Sumo Logic official documentation*](https://help.sumologic.com/03Send-Data/Installed-Collectors/04Install-a-Collector-on-Linux)*.*

Once the collector is installed, it appears under **Manage** → **Collection**.

![Collector_Appears_in_Sumo_Logic.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/17734724787988.png)

**Figure 4: Collector appears in sumo logic**

### 3.5 Configuring Syslog Server

#### 3.5.1 Configuring Syslog Server in Sumo Logic

Perform the following steps:

1. Click **Manage Data** → **Collection**.
2. Click **Edit** next to **Syslog Server**.
3. Select **Protocol** as **TCP**, **Port** as **514**, leave the rest of the settings as default, and then click **Save**.

![Configure_the_Connector_in_Sumo_Logic.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/6398439941908.png)

**Figure 5: Configure the connector in sumo logic**

#### 3.5.2 Configuring Syslog Server in Fortanix DSM

Perform the following steps to configure logging events to the Syslog:

1. In the **Custom Log Management Integrations** section, click **ADD INTEGRATION** for Syslog.
2. On the **Syslog Log Management Integration** form:
  - **Host**: Enter the hostname or IP address of your Syslog server.
    - **Enable TLS**: Select this check box to communicate with the Syslog server over a secure connection using TLS.
    - **Host validation**: Select the **Validate host** check box to ensure that the Syslog server hostname mentioned above matches the hostname specified in the server certificate. To skip hostname verification, clear the **Validate host** check box.
    - **Validate certificate**: You can connect to the Syslog server over a non-secure connection or a secure TLS connection. Depending on the type of TLS certificate that the Syslog server is using:
      - If you are using a certificate signed by a well-known public CA, select **Global Root CAs**.
      - If your organization uses a self-signed certificate issued by an internal Certificate Authority (CA), select **Custom CA Certificate**. Click **UPLOAD A FILE** to upload your CA certificate. When Fortanix DSM, acting as a client, connects to the Syslog server and receives the server’s certificate, it validates the certificate using the uploaded custom CA certificate.
  - **Port (TCP)**: The default port for the Syslog server is **514**. If you are using a different port, update the port number accordingly.
  - **Facility**: When you log an event in Syslog, you can choose to log it in different facilities. Use this setting to filter logs by a specific facility, such as **User**, **Local0**, **Local1**, and others that are well-defined in the Syslog protocol. For example, configure Fortanix DSM to use the **Local0** facility to easily filter logs from a specific appliance.
3. Click **SAVE** to add the Syslog integration.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/LogManagement_Syslog_Server_Form(2).png)

**Figure 6: Configure syslog server**

### 3.6 Viewing Audit Logs in Sumo Logic

Once all the above steps are completed, you can see all the audit logs in the Sumo Logic Screen.

![View_Audit_Logs_in_Sumo_Logic.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/17734754261396.png)

**Figure 7: View audit logs in sumo logic**

You can further customize the data and chart by writing a query in the search bar. For example,

```bash
_sourceCategory="Fortanix" and _collector="sumologictest" |
logreduce
| timeslice 1h
| count by _timeslice
| order by _timeslice
```

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.

## Related

- [Fortanix DSM with LogRhythm](/fortanix-dsm-with-logrhythm.md)
