EDR: How to Change Syslog Output to CEF Format
search cancel

EDR: How to Change Syslog Output to CEF Format


Article ID: 285764


Updated On:


Carbon Black EDR (formerly Cb Response)


Change the Syslog so that it outputs in CEF format 


On-Premise EDR: 6.x or Higher 


  1. CEF syslog templates are located at /usr/share/cb/syslog_templates. If you plan to modify them, copy to a custom directory. To use them, add the following lines to /etc/cb/cb.conf: 
  2. The watchlist searcher process will automatically pick up the new template when the next watchlist hit occurs.
  3. Additional Options exist for Syslog Templates and Output Parameters.  More information can be found here.

Additional Information

  • The Common Event Format is an ArcSight standard that aligns the output format of various technology vendors into a common form.
  • EDR watchlist syslog output supports fully-templated formats, which enables easy modification of the template to match the CEF-defined format.
  • CEF is only available through native Rsyslog and not through the Event Forwarder.
  • If you custom modify the CEF templates, move them into a custom directory and point the config to the new directory. This will avoid the templates being overwritten during an upgrade.