Standard Event Format (SEF) is a JavaScript Object Notation (JSON)-based event format to represent generic event data. SEF format forwards events from one Trellix ESM to a receiver on a different Trellix ESM, and from the Trellix ESM to a third party. You can also use it to send events from a third party to a receiver by selecting SEF as the data format when creating the data source.
When setting up event forwarding with SEF from one Trellix ESM to another Trellix ESM, complete the following steps:
From the Trellix ESM that is forwarding the events, export data sources, custom types, and custom rules.
On the Trellix ESM with the receiver you are forwarding events to, import the data sources, custom types, and custom rules that you exported.
On the Trellix ESM receiving the events from another Trellix ESM, add a Trellix ESM data source.
On the sending Trellix ESM, add the event forwarding destination as follows:
From the Trellix ESM dashboard, click
and select More Settings.On the system navigation tree, select Trellix ESM and click
.Click Event Forwarding, then click Add.
On the Add Event Forwarding Destination page, select syslog (Standard Event Format) in the Format field, then complete the remaining fields with the information for the Trellix ESM you are forwarding to, and click OK.