Before enabling export of events in CEF format, it is recommended to specify a category (facility) for syslog that is not used by other programs on the server.
To enable export of events in CEF format:
<siemSettings> section, specify one of the following values of the <facility> parameter:AuthAuthprivCronDaemonFtpLprMailNewsSyslogUserUucpLocal0Local1Local2Local3Local4Local5Local6Local7By default, the value is set to Mail.
Example:
|
<siemSettings> section, set the value of the <enabled> parameter to 1.Example:
|