Use the Rsyslog Settings area to set up the default configuration for rsyslog notifications.
On the Web UI, select the Settings tab.
Select Notifications on the side bar.
Click the rsyslog column heading to display the Rsyslog Settings area in the Settings column.
.png)
Select Common Event Format (CEF), Log Event Enhanced Format (LEEF), Comma-Separated Values (CSV), XML, JSON, Text, Text Normal, Text Concise, Text Extended, JSON Normal, JSON Concise, JSON Extended, XML Normal, XML Concise, XML Extended, JSON legacy concise, JSON legacy extended, JSON legacy normal, or Secureworks as the default format and select which level of detail (only for XML, JSON, or text) is provided in the Default format drop-down list box:
Normal—This format contains detailed information and abstracts, such as alert type, ID, source IP, malware name, hostname, and alert URL without redundant information.
Concise—This format contains basic information, such as alert type, ID, source IP, malware name, hostname, and alert URL.
Extended—This format contains detailed information and abstracts, including data-theft information (if any) and static-analysis details. This format provides all details about files and objects modified during analysis.
Select the default severity classification for the rsyslog notification:
Alert—Action must be taken immediately (severity 1).
Critical—Critical conditions (severity 2).
Debug—Debug-level messages (severity 7).
Emergency—Emergency: system is unusable (severity 0).
Error—Error conditions (severity 3).
Informational—Informational messages (severity 6).
Notice—Normal but significant conditions (severity 5).
Warning—Warning conditions (severity 4).
To apply the rsyslog settings, click Apply Settings.
Note
If you do not click Apply Settings, your changes are lost.