After navigating to Settings > Communication > Advanced and checking the Remote Syslog box next to Alert Events (and clicking Save), you notice that your syslog server is still not receiving any alert event logs from Security Analytics.
While enabling Remote Syslog under the Communication > Advanced settings globally activates the communication channel for these events, it does not automatically bind your individual alerts to it.
To successfully route alert events to your syslog server, you must configure each specific alert definition to use the syslog channel and assign an appropriate alert template to it.
To resolve this issue, you must configure individual alerts to send syslog notifications. Follow these steps:
Navigate to Analyze > Rules in the main menu.
Select and edit the specific alert/rule you wish to send to your syslog server.
Locate the Notification or Actions section within the alert's configuration settings.
Check the box to enable Syslog for this specific alert.
Select the desired Alert Template from the dropdown menu (this dictates how the syslog message is formatted).
Save the changes to the alert.
Note: You must repeat these steps for each individual alert you want to monitor via your syslog server. If no template is assigned or the syslog action is unchecked on the alert itself, no payload will be sent.