Share XDR data with your syslog server by configuring the generic syslog connector.
This is a “Pre-release” feature and is not considered an official release. Please review the Pre-release Disclaimer before using the feature.
The syslog connector is a generic SIEM connector, which allows you to send XDR data to your on-premises syslog server. The connector supports multiple syslog server connections.
For syslog CEF mapping, see Syslog Content Mapping - CEF.
Category |
Vendor |
Associated Apps |
---|---|---|
SIEM |
Not applicable |
|
Workbench alerts
Observed Attack Techniques
You must select at least one data type.
Setting |
Description |
---|---|
Server address |
Specify the IP address or FQDN for your syslog server. |
Syslog format |
Select the syslog format. Note:
Syslog Connector (On-premises) currently only supports Common Event Format (CEF). |
Protocol |
Select the connection protocol. |
Port |
Specify the port. Default port settings:
|