Make sure to enable the export of events in CEF format before you proceed with the configuration.
Follow the steps described below on each cluster node for which you want to have events published to a SIEM system.
To configure the publication of application events to a SIEM system:
$ActionQueueFileName ForwardToSIEM
$ActionQueueMaxDiskSpace 1g
$ActionQueueSaveOnShutdown on
$ActionQueueType LinkedList
$ActionResumeRetryCount -1
<facility>.* @@<IP address of the SIEM system>:<port on which the SIEM system receives messages from Syslog over TCP>
It is recommended to create a backup copy of the /etc/rsyslog.conf file before editing it. A mistake introduced while editing the file can cause the system to malfunction.
service rsyslog restart
The publishing of events to a SIEM system is configured.
Page top