AI security & operations for MSPs

Network Devices

What Hal reads

Routers, firewalls, switches, wireless controllers and any other device that can send syslog feed Hal through a Hal collector on the device’s own LAN. The flow is one-way in: the device sends, the collector forwards, Hal receives. He never reaches back into the devices, and nothing is installed on them.

Everything a device sends is kept. Every record holds the whole line as it arrived, so nothing is lost to a format the parser did not expect. The events are searchable alongside the client’s cloud and endpoint sources, read by the same triage pipeline, and retained 365 days like every other source.

How it reaches Hal

The collector is the same Windows endpoint collector every other host runs, installed on one always-on Windows machine per site with the -syslog option. That host keeps shipping its own Windows event logs and, in addition, listens for syslog on the LAN, UDP and TCP, port 514 by default. Every device at the site points its syslog at that host’s LAN address. The collector stamps each record with the client it was installed for and forwards it over HTTPS to your deployment’s collector address, the exact path Windows events already travel.

So the network side of a site needs:

  • nothing installed on the devices;
  • no inbound port on the internet, no VPN and no relay of your own;
  • outbound HTTPS on port 443 from the collector host, which it already has.

One collector takes any number of devices. A client with one site needs one collector. A client with five sites needs one per site, or one for several sites if their LANs route to each other. Two collectors at one client are simply two host names on otherwise identical records.

What each record carries

A syslog line says which hostname claims to have sent it and nothing else. The collector adds what it knows:

FieldWhat it is
ClientThe client the collector was installed for: chosen by a person, checked against your client list at install, and guarded against accidental reassignment
DeviceThe hostname in the syslog header, and the device’s LAN address as the sender
CollectorWhich host forwarded the record, by name and by its machine identity
TransportUDP or TCP
Device timeThe device’s own timestamp, kept as it was written
RawThe whole line, exactly as received

Two consequences matter. Where a line is filed is decided by the collector, not by the device. Every line reaching a site’s collector goes into the records of the client that collector was installed for, the one whose UID was on the install command, whatever the device calls itself. A renamed or misnamed firewall cannot put its logs under another client. And the event time is when the collector received the line, which on a LAN is within milliseconds of when the device sent it. Devices disagree about years, time zones and formats in their own timestamps, so those are kept for forensics rather than trusted for ordering.

Formats

The collector’s parser accepts every line. It recognises the header shapes of RFC 5424 and RFC 3164 syslog, of Cisco Meraki and of Fortinet FortiGate, and takes the device hostname, the device’s timestamp and the message out of each. A line in any other shape is kept whole, shown under the sender’s address, and reaches Hal like any other. Nothing is dropped for its format.

Setting it up

  1. Pick the host. Any 64-bit Windows machine at the site that stays on and is not a domain controller. A management or utility server is the usual choice; a workstation works if it is never switched off or put to sleep, because most devices do not retry syslog, so whatever they send while the collector is down is gone. The listener is open to the whole LAN and runs as SYSTEM, so -syslog is refused on a domain controller and there is no override. If the site’s only server is the DC, give it a small utility host.

  2. Install the collector with -syslog. From the host or from your RMM, with the client’s UID as for any other endpoint:

    hal-collector-setup.exe -silent -client cli_01kwfenm48fzkr9kdepq9thrwr -syslog
    

    If another product already receives syslog on 514 on that host, choose a port:

    hal-collector-setup.exe -silent -client cli_01kwfenm48fzkr9kdepq9thrwr -syslog -syslog-port 5514
    

    The installer opens Windows Firewall for the collector on that port: two inbound rules named Hal collector syslog (UDP) and Hal collector syslog (TCP), scoped to the collector executable and accepting any remote address, because devices are often on other VLANs than servers. A domain GPO that manages the host firewall may override them; if it does, allow the port in the GPO. Run without -silent and the installer says which port it is listening on. Keep -syslog on every later run of the installer on this host: the command line is the truth each time, so a run without it, such as your fleet-wide RMM job, turns the listener off and removes the firewall rules.

  3. Point the devices at it. On each firewall, switch or controller, set the remote syslog target to the collector’s LAN address, UDP or TCP, on the port you chose.

Verifying

A device appears on Logs → Network under its hostname, or under its address when the header carries none, on the next detection cycle after its first line arrives, within a few minutes. Its row shows the address it sent from, the collector that forwarded it, the transport and the time of its last event, and Hal gives it a Device ID of its own, because a syslog device carries no identity of its own that a record could show. A device that is renamed or given a new address therefore appears as a new row while the old one goes quiet. Hal can list a client’s devices in chat as this page shows them, merge the old row into the new one when you ask, or remove a device that is gone.

Rows of the Network table in Hal's portal: each device's host name or address, a Device ID beginning dev_, the LAN address it sent from, a Collector pill naming the management server that forwarded it, and a Transport column reading syslog-udp or syslog-tcp
Logs → Network. Every device names the collector that forwarded it, the address it sent from and the transport. A device with no hostname in its syslog header is listed by its address. Open the figure for the whole tab.

The collector host shows syslog :514, or your port, in the Collector column of Logs → Endpoints after its next heartbeat, within 15 minutes, and the tab’s Collector filter pill lists only the hosts that collect their site’s syslog.

Three rows of the Endpoints table in Hal's portal, filtered to the site collectors: hosts mhg-MGMT01, ml-MGMT01 and whh-MGMT01, each a Windows server with its agent version and a Version value, and a Collector column reading syslog :514 for the first two and syslog :5514 for the third
Logs → Endpoints, filtered by the Collector pills. One host per site collects the site’s syslog, here each site’s management server, and the pill shows the port it listens on. Open the figure for the whole table, filter bar included.

A device that sends nothing for more than 24 hours is flagged as a possible coverage gap.

If a device is sending and nothing appears, the collector writes its own log at C:\Program Files\fluent-bit\fluent-bit.log on the host.

Changing or removing the collector

The command line is the truth on every run. A re-run without -syslog turns the listener off and removes its firewall rules, so the RMM job that refreshes a collector host must carry the flag: the site’s collector job differs from the fleet job by that flag alone. On its next heartbeat the host’s Collector column clears. -uninstall removes the collector, Fluent Bit and the firewall rules together. Never remove a collector by deleting its directory: that deletes the host’s identity file, and every device it collects for reappears as a second row. The rule in full is on the Windows endpoints page.

See also: the Windows endpoints guide for every installer option, the SIEM and read-only by architecture.

See what Hal surfaces on your own clients.

No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.

  1. 01You ask us your questions. No deck, no demo dataset.
  2. 02You sign a short evaluation agreement, and we stand up your own instance.
  3. 03You connect one tenant from your own admin console. Hal watches it for 14 days.
  4. 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.