cancel
Showing results for 
Search instead for 
Did you mean: 
anas.ismail
Level 9

Sending Syslog to More than one SIEM Receiver

Hi

We have two SIEM solutions McAfee Nitro And Arcsight in the environment, Now we are sending the access logs in CEF format to our Arcsight receiver, Can we send the syslog to both Arcsight in CEF format and for McAfee Nitro ELM ?! and if possible how to configure this ?!

Thanks

Anas 

0 Kudos
2 Replies
anas.ismail
Level 9

Re: Sending Syslog to More than one SIEM Receiver

Gentle Reminder

0 Kudos
eelsasser
Level 15

Re: Sending Syslog to More than one SIEM Receiver

Configure one for level 6 (info):

Syslog (6, User-Defined.logLine)

Configure the second one for level 5 (notice):

Syslog (5, User-Defined.logLine)

Set your rsyslog.conf to sent to the applicable server

daemon.notice @192.168.1.10

daemon.info @192.168.1.20

make sure you exclude writing both info and notice to disk:

*.info;daemon.!=info;daemon.!=notice;mail.none;authpriv.none;cron.none-/var/log/messages
0 Kudos