We have 10 MWG appliances need to be monitored through our SIEM solution (Arcsight), we have configured the access logs to be send via syslog in CEF format to the Arcsight, and it worked, now we are trying to send the audit logs, alerts and MWG errors through syslog also, any suggestions please ?!
Solved! Go to Solution.
have you had any luck in setting fields for the CEF format to Arcsight?
We would like to have more fields but we cannot map them correctly.