Events are sent from the Sendmail mail agent server to the KUMA collector using the rsyslog service.
To configure transmission of Sendmail events to the collector:
If $programname contains 'sendmail' then @<<IP address of the collector>:<port of the collector>>
Example:
|
If you want to send events via TCP, the contents of the file must be as follows:
If $programname contains 'sendmail' then @@<<IP address of the collector>:<port of the collector>>
$IncludeConfig /etc/Sendmail-to-siem.conf
$RepeatedMsgReduction off
sudo systemctl restart rsyslog.service