For 3, it is actually a 4 hour window or 5 MB, which ever happens first. I believe this was changed in 9.1.3.
Thank you very much for information.
Is there any reference regarding ELM time window above?
I haven't seen it in Release Note or ESMI User Guide, anyway.
For (2), do you have any experience or useful information sharing about practical value for events pulling interval?
Did you ever get any further with this?
We are starting to see some use cases where a reduced lag is desirable and I have been looking at the 10 minute interval and wondering whet the effects of reducing this would be.
Does anyone have experience with this?
can someone tell us how to download the SIEM agent? can someone share it?
You can grab the SIEM agent from the Downloads section in the Customer Portal.
Like someone else said, it is under Downloads in the Customer Portal. It is under the "Receiver" downloads.