Configuring rsyslog settings

Prev Next

Use the Define protocol settings section on the RSYSLOG tab of the Notification Settings page to configure default settings for rsyslog notifications.

All_RsyslogFormat_scap.PNG
To configure rsyslog settings:
  1. Click the Settings tab.

  2. Select Notifications on the side bar.

  3. Click the RSYSLOG tab.

  4. Select Common Event Format (CEF), Log Event Enhanced Format (LEEF), Comma-Separated Values (CSV), XML, JSON, or Text as the default format and select which level of detail (only for XML, JSON, or text) is provided in the Default format drop-down list box:

    • Normal—This format contains detailed information and abstracts, such as alert type, ID, source IP, malware name, hostname, and alert URL without redundant information.

    • Concise—This format contains basic information, such as alert type, ID, source IP, malware name, hostname, and alert URL.

    • Extended—This format contains detailed information and abstracts, including data-theft information (if any) and static-analysis details. This format provides all details about files and objects modified during analysis.

  5. Per event is selected in the Default delivery drop-down list box. This sends a notification each time an event of this type occurs.

  6. Select the severity classification for the Rsyslog notification in the Default send as box:

    • Alert—Action must be taken immediately (severity 1).

    • Critical—Critical conditions (severity 2).

    • Debug—Debug-level messages (severity 7).

    • Emergency—Emergency: system is unusable (severity 0).

    • Error—Error conditions (severity 3).

    • Informational—Informational messages (severity 6).

    • Notice—Normal but significant conditions (severity 5).

    • Warning—Warning conditions (severity 4).

  7. Click Apply Settings.

    Note

    If you do not click Apply Settings, your changes are lost.