Alert notifications in all formats (XML, JSON, CEF, LEEF, and so on) are configurable in “concise,” “extended,” or “normal” outputs. These output options offer different levels of detailed information about a particular alert.
Notifications formatted with the “normal” output are the same as “concise” but also include OS Changes, callback details, and malware details if available. Extended outputs are the same as “normal” but also include data theft and static analysis information, if available.
Note
If you are sending alert notifications in XML or JSON to a rsyslog server using the extended output option, the size of the alert notification is likely to exceed the 4K UDP limit. To avoid this limit, use TCP as the transportation layer instead of UDP.
File Protect (FX) > File Protect 10.x > File Protect 10.x Product Guide > Using the product > Event notifications > Configuring event notifications using the Web UI > Configuring rsyslog notifications using the Web UI
File Protect (FX) > File Protect 11.x > File Protect 11.x Product Guide > Using the product > Event notifications > Configuring event notifications using the Web UI > Configuring rsyslog notifications using the Web UI