Environment
On-Premise EDR: 6.x or Higher
Objective
Change the Syslog so that it outputs in CEF format
Resolution
- CEF syslog templates are located at /usr/share/cb/syslog_templates. To use them, add the following lines to /etc/cb/cb.conf:
WatchlistSyslogTemplateProcess=/usr/share/cb/syslog_templates/process_cef.txt
WatchlistSyslogTemplateBinary=/usr/share/cb/syslog_templates/binary_cef.txt
- The watchlist searcher process will automatically pick up the new template when the next watchlist hit occurs.
- Additional Options exist for Syslog Templates and Output Parameters. More information can be found here.
Additional Notes
- The Common Event Format is an ArcSight standard that aligns the output format of various technology vendors into a common form.
- EDR watchlist syslog output supports fully-templated formats, which enables easy modification of the template to match the CEF-defined format.
- CEF is only available through native Rsyslog and not through the Event Forwarder.
Related Content