You can access more servers by registering them with your ePO - On-prem server. Registered servers allow you to integrate your software with other external servers.
Add the syslog server as a registered server and send information (responses or Solidcore events) to the syslog server.
Add the syslog server as a registered server.
On the ePO - On-prem console, select Menu → Configuration → Registered Servers, then click New Server to open the Registered Server Builder wizard.
Select Solidcore Syslog Server from the Server type list.
Specify the server name, add any notes, then click Next.
(Optional) Change the syslog server port.
Enter the server address.
You can choose to specify the DNS name, IPV4 address, or IPv6 address.
Select the type of logs the server is configured to receive by selecting a value from the Syslog Facility list.
Click Test Syslog send to verify the connection to the server.
Click Save.
You can choose to send specific responses to the syslog server (complete step 2) or use the seeded response to send all Solidcore events to the syslog server (complete step 3).
Send responses to the syslog server.
Select Menu → Automation → Automatic Responses.
Click Actions → New Response.
Enter the alert name.
Select the ePO Notification Events group and Threat event type.
Select Enabled, then click Next to open the Filter page.
Define the relevant filters, then click Next to open the Aggregation page.
Specify aggregation details, then click Next to open the Actions page.
Select the Send Event To Solidcore Syslog action.
Specify the severity and message.
You can use the listed variables to create the message string.
Select the appropriate syslog servers (one or more), then click Next.
Review the response details, then click Save.
Send all Solidcore events to the syslog server.
Application and Change Control and include a seeded response that you can configure to automatically send all Solidcore events to the syslog server.
Select Menu | Automation | Automatic Responses.
Edit the Send Solidcore events to Syslog Server response to configure these options.
Set the status to Enabled.
Verify that the appropriate syslog server is selected.
Review the message string.
The message string is based on the Common Exchange format. Contact Trellix Support for assistance in understanding the message string.
Save the response.