Within Varonis DatAlert, the default Alert Template for syslog messages contains line feeds and carriage returns. Most syslog parsers have a much easier time dealing with single line messages. If you are going to send Varonis alerts to syslog you should create a template specifically for that. Here is a sample that I work with.
No comments:
Post a Comment