The CB PSC Syslog Connector requires the use of a SIEM and API Access Level API Keys.
If using multiple Cb Defense Servers for this SIEM, you can configure additional servers with their connector_id, api_key, and server_url at the bottom of the config file. An example is included by default. For further help, see: https://community.carbonblack.com/t5/Knowledge-Base/Cb-Defense-How-to-configure-the-Syslog-Connector-to-pull-data/ta-p/39857
The leef output version is only version 2.0. version 1.0 is not supported
For the Syslog Connector to pull information a Notification needs to be setup because it will pull the Alert and Associated Information only for Notifications that were sent. Notifications can be setup per https://community.carbonblack.com/t5/Knowledge-Base/Carbon-Black-Cloud-How-to-Add-New-Notifications/ta-p/38863