# Vendors

Onboard vendor-specific source devices and hosts to Axoflow so they appear on the Topology page, send logs to AxoRouter, and report host metrics.

## Prerequisites

  * You have administrative access to the source device or host.
  * You have an [AxoRouter deployed and configured](../../docs/axoflow/0.81/provisioning/axorouter/index.md) with a [Syslog connector](../../docs/axoflow/0.81/data-sources/syslog/index.md) that has parsing and classification enabled (by default, every AxoRouter has such connectors). This device is going to receive the data from the source device or host.
  * You know the IP address the AxoRouter. To find it:

    1. Open the AxoConsole.
    2. Select the **Routers** or the **Topology** page.
    3. Select on AxoRouter instance that is going to receive the logs.
    4. Check the **Networks > Address** field.



## Onboard a vendor source

To onboard sources that are specifically supported by Axoflow, complete the following steps. Onboarding allows you to collect metrics about the host, and display the host on the **Topology** page.

  1. Open the AxoConsole.

  2. Select **Topology**.

  3. Select **Add Item > Source**.

![Add appliance as source](/docs/axoflow/0.81/img/topology/add-source_hu_81754123db001cd2.webp)

  4. Add the source to AxoConsole using one of the following methods:

     * If the source is already sending logs to an AxoRouter instance that is registered in the AxoConsole, select **Detected** , then select the source.

You can add multiple detected sources in a single step in bulk.

![Add detected data source](/docs/axoflow/0.81/img/topology/add-detected-source_hu_90c1e78666396048.webp)

     * Otherwise, select the type of the source you want to onboard, and follow the on-screen instructions.

![Select data source](/docs/axoflow/0.81/img/topology/select-appliance_hu_6895cd06d92971e.webp)

  5. Connect the source to the destination or AxoRouter instance it’s sending logs to. If you’ve added the source from the **Detected** list, you can skip this step, as the path is created automatically.

     1. Select **Topology > Add Item > Path**.

![Add a new path](/docs/axoflow/0.81/img/data-management/flow-management/paths/add-path_hu_bedfdb7f0050673a.webp)

     2. Select the target router or aggregator this source is sending its data to in the **Target host** field, for example, `axorouter`.

     3. Select the **Target connector**. The connector determines how the destination receives the data (for example, using which protocol or port).

     4. Select **Add**. The new path appears on the **Topology** page.

![The new path](/docs/axoflow/0.81/img/data-management/flow-management/paths/path-created_hu_8e6634dca1ed0d1a.webp)

  6. If you haven’t already done so, configure the source to send logs to an AxoRouter instance. For vendor-specific configuration steps, default metadata (labels), and SIEM-specific metadata, see the page for each source.

Note

Unless instructed otherwise, configure your source to send the logs to the [Syslog](../../docs/axoflow/0.81/data-sources/syslog/index.md) connector of AxoRouter, using the appropriate port. Use RFC5424 if the source supports it.

     * 514 UDP and TCP for RFC3164 (BSD-syslog) and RFC5424 (IETF-syslog) formatted traffic. AxoRouter automatically recognizes and handles both formats.
     * 601 TCP (RFC 3195 - Reliable Delivery for syslog) for RFC5424 (IETF-syslog) and RFC3164 (BSD-syslog) formatted traffic. AxoRouter automatically recognizes and handles both formats.
     * 6514 TCP for TLS-encrypted syslog traffic (RFC 5425).




* * *

[A10 Networks](../../docs/axoflow/0.81/data-sources/appliances/a10networks/index.md)

[Amazon](../../docs/axoflow/0.81/data-sources/appliances/amazon/index.md)

[Axoflow](../../docs/axoflow/0.81/data-sources/appliances/axoflow/index.md)

[Broadcom](../../docs/axoflow/0.81/data-sources/appliances/broadcom/index.md)

[Check Point](../../docs/axoflow/0.81/data-sources/appliances/checkpoint/index.md)

[Cisco](../../docs/axoflow/0.81/data-sources/appliances/cisco/index.md)

[Citrix](../../docs/axoflow/0.81/data-sources/appliances/citrix/index.md)

[Corelight](../../docs/axoflow/0.81/data-sources/appliances/corelight/index.md)

[CrowdStrike](../../docs/axoflow/0.81/data-sources/appliances/crowdstrike/index.md)

[CyberArk](../../docs/axoflow/0.81/data-sources/appliances/cyberark/index.md)

[Elastic](../../docs/axoflow/0.81/data-sources/appliances/elastic/index.md)

[F5 Networks](../../docs/axoflow/0.81/data-sources/appliances/f5/index.md)

[FireEye](../../docs/axoflow/0.81/data-sources/appliances/trellix/index.md)

[Forcepoint](../../docs/axoflow/0.81/data-sources/appliances/forcepoint/index.md)

[Fortinet](../../docs/axoflow/0.81/data-sources/appliances/fortinet/index.md)

[Fortra](../../docs/axoflow/0.81/data-sources/appliances/fortra/index.md)

[General Unix/Linux host](../../docs/axoflow/0.81/data-sources/appliances/nix/index.md)

[Imperva](../../docs/axoflow/0.81/data-sources/appliances/imperva/index.md)

[Infoblox](../../docs/axoflow/0.81/data-sources/appliances/infoblox/index.md)

[Ivanti](../../docs/axoflow/0.81/data-sources/appliances/ivanti/index.md)

[Juniper](../../docs/axoflow/0.81/data-sources/appliances/juniper/index.md)

[Kaspersky](../../docs/axoflow/0.81/data-sources/appliances/kaspersky/index.md)

[Kubernetes](../../docs/axoflow/0.81/data-sources/appliances/kubernetes/index.md)

[MicroFocus](../../docs/axoflow/0.81/data-sources/appliances/opentext/index.md)

[Microsoft](../../docs/axoflow/0.81/data-sources/appliances/microsoft/index.md)

[MikroTik](../../docs/axoflow/0.81/data-sources/appliances/mikrotik/index.md)

[NetFlow Logic](../../docs/axoflow/0.81/data-sources/appliances/netflow/index.md)

[Netgate](../../docs/axoflow/0.81/data-sources/appliances/netgate/index.md)

[Netmotion](../../docs/axoflow/0.81/data-sources/appliances/netmotion/index.md)

[NETSCOUT](../../docs/axoflow/0.81/data-sources/appliances/netscout/index.md)

[Omnissa](../../docs/axoflow/0.81/data-sources/appliances/omnissa/index.md)

[OpenText](../../docs/axoflow/0.81/data-sources/appliances/opentext/index.md)

[Palo Alto Networks](../../docs/axoflow/0.81/data-sources/appliances/palo-alto/index.md)

[Ping Identity](../../docs/axoflow/0.81/data-sources/appliances/ping-identity/index.md)

[Powertech](../../docs/axoflow/0.81/data-sources/appliances/fortra/index.md)

[Progress](../../docs/axoflow/0.81/data-sources/appliances/progress/index.md)

[Riverbed](../../docs/axoflow/0.81/data-sources/appliances/riverbed/index.md)

[RSA](../../docs/axoflow/0.81/data-sources/appliances/rsa/index.md)

[rsyslog](../../docs/axoflow/0.81/data-sources/appliances/rsyslog/index.md)

[SecureAuth](../../docs/axoflow/0.81/data-sources/appliances/secureauth/index.md)

[Skyhigh Security](../../docs/axoflow/0.81/data-sources/appliances/skyhigh/index.md)

[SonicWall](../../docs/axoflow/0.81/data-sources/appliances/dell/index.md)

[Splunk](../../docs/axoflow/0.81/data-sources/appliances/splunk/index.md)

[Superna](../../docs/axoflow/0.81/data-sources/appliances/superna/index.md)

[syslog-ng](../../docs/axoflow/0.81/data-sources/appliances/syslog-ng/index.md)

[Tanium](../../docs/axoflow/0.81/data-sources/appliances/tanium/index.md)

[Thales](../../docs/axoflow/0.81/data-sources/appliances/thales/index.md)

[Trellix](../../docs/axoflow/0.81/data-sources/appliances/trellix/index.md)

[Trend Micro](../../docs/axoflow/0.81/data-sources/appliances/trend-micro/index.md)

[Ubiquiti](../../docs/axoflow/0.81/data-sources/appliances/ubiquity/index.md)

[Varonis](../../docs/axoflow/0.81/data-sources/appliances/varonis/index.md)

[Vectra AI](../../docs/axoflow/0.81/data-sources/appliances/vectra/index.md)

[Zscaler appliances](../../docs/axoflow/0.81/data-sources/appliances/zscaler/index.md)