CEF Syslog Feedback

The broker component can be configured to send a CEF syslog summary string to any endpoint via TCP or UDP.

The CEF syslog feedback is generated and sent to the configured endpoint when the main transform task and all its subtasks are in a final processing state.

To modify the syslog feedback configuration:

Step #1 - Open /home/sandbox/sandbox/broker.cfg in a text editor

Step #2 - Add or modify the following properties (no need to overwrite default values):

broker.cfg
Copy

Step #3 - Save the file and restart the sandbox service

Property details

Property NameDefault ValueDescription
cefSyslogEnabledfalseMain switch to enable / disable CEF syslog feedback
cefSyslogHost-Host name or IP address of the log server
cefSyslogPort514Port of the log server
cefSyslogProtocoltcpConnection protocol to use: tcp or udp
cefSyslogTimeoutMs10 secondsConnection timeout used for TCP sockets
cefSyslogUseSSLfalseSwitch to enable / disable SSL verification for TCP sockets

Example CEF syslog string:

message
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard