Before enabling export of events in CEF format, it is recommended to specify a category (facility) for syslog that is not used by other programs on the server.
To enable export of events in CEF format:
<siemSettings>
section, specify one of the following values of the <facility>
parameter:Auth
Authpriv
Cron
Daemon
Ftp
Lpr
Mail
News
Syslog
User
Uucp
Local0
Local1
Local2
Local3
Local4
Local5
Local6
Local7
By default, the value is set to Mail
.
Example:
|
<siemSettings>
section, set the value of the <enabled>
parameter to 1
.Example:
|