SIEM configuration

Hello community,

I’m having an hard time trying to configure syslog events forwarding. I’ve already enabled it from the .yml file but still can’t find a way to configure it to send the logs directly to my SIEM (I’ve already tried to forward the file via rsyslog, it is not the solution I’m looking for).

Thanks in advance for the help or suggestions

can someone explain how to point the logs to syslog server?


There is no support for an external server though. But you can configure that on the host it self i think.