IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How to Change Syslog Output to CEF Format

EDR: How to Change Syslog Output to CEF Format

Environment

On-Premise EDR: 6.x or Higher 

Objective

Change the Syslog so that it outputs in CEF format 

Resolution

  1. CEF syslog templates are located at /usr/share/cb/syslog_templates. To use them, add the following lines to /etc/cb/cb.conf: 
    WatchlistSyslogTemplateProcess=/usr/share/cb/syslog_templates/process_cef.txt 
    WatchlistSyslogTemplateBinary=/usr/share/cb/syslog_templates/binary_cef.txt
  2. The watchlist searcher process will automatically pick up the new template when the next watchlist hit occurs.
  3. Additional Options exist for Syslog Templates and Output Parameters.  More information can be found here.

Additional Notes

  • The Common Event Format is an ArcSight standard that aligns the output format of various technology vendors into a common form.
  • EDR watchlist syslog output supports fully-templated formats, which enables easy modification of the template to match the CEF-defined format.
  • CEF is only available through native Rsyslog and not through the Event Forwarder.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎12-18-2018
Views:
3929
Contributors