Change the Syslog so that it outputs in CEF format
Environment
On-Premise EDR: 6.x or Higher
Resolution
CEF syslog templates are located at /usr/share/cb/syslog_templates. If you plan to modify them, copy to a custom directory. To use them, add the following lines to /etc/cb/cb.conf:
The watchlist searcher process will automatically pick up the new template when the next watchlist hit occurs.
Additional Options exist for Syslog Templates and Output Parameters. More information can be found here.
Additional Information
The Common Event Format is an ArcSight standard that aligns the output format of various technology vendors into a common form.
EDR watchlist syslog output supports fully-templated formats, which enables easy modification of the template to match the CEF-defined format.
CEF is only available through native Rsyslog and not through the Event Forwarder.
If you custom modify the CEF templates, move them into a custom directory and point the config to the new directory. This will avoid the templates being overwritten during an upgrade.