How to customize Syslog templates in Carbon Black EDR
/usr/share/cb/cbsyslog -g
/usr/share/cb/syslog_templates
BinaryInfoSyslogTemplateGroupObserved=<path and filename>
BinaryInfoSyslogTemplateHostObserved=<path and filename>
BinaryInfoSyslogTemplateObserved=<path and filename>
FeedIngressSyslogTemplateBinary=<path and filename>
FeedIngressSyslogTemplateProcess=<path and filename>
FeedIngressSyslogTemplateHost=<path and filename FeedStorageSyslogTemplateBinary=<path and filename> FeedStorageSyslogTemplateProcess=<path and filename> WatchlistSyslogTemplateBinary=<path and filename> WatchlistSyslogTemplateProcess=<path and filename> FeedQuerySyslogTemplateBinary=<path and filename> FeedQuerySyslogTemplateProcess=<path and filename>
<tag>='{{doc["<key>"]}}
<tag>:{{doc["<key>"]|cef_escape}}