Skip to content
Discussion options

You must be logged in to vote

I wanted to close the loop on this discussion and say that I got it working. Here's the instructions.

These instructions will allow the 'Receiver' node to accept incoming CEF formatted logs. If you want a different grid node to be defined, adjust accordingly.

  1. Open 'Elastic Fleet' from SO sidebar.
    Open 'Integrations' from Elastic sidebar.
    Find the 'CEF' integration.
    Click 'Add Common Event Format (CEF)' blue button from top right.

    Set the following settings:
    input: udp Syslog Host 0.0.0.0
    Syslog Port 9003
    input: tcp Syslog Host 0.0.0.0
    Syslog Port 9004

    Existing hosts Agent policies so-grid-nodes_general

    'Save and continue'
    'Save and deploy changes'

  2. Open 'Administration> Configuration> …

Replies: 3 comments 2 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
2 replies
@kspringer-maf
Comment options

@InfosecGoon
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by kspringer-maf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants