Hello All,
I'm using SEP v14.
And I'm trying to forward SEP Syslogs to our SIEM.
But, I can't find Syslog format. To normalize in our SIEM, I have to know about syslog format which is coming in SIEM.
After nomalizing, we can monitor it with this.
Also, I'm trying to get Windows Event ID to monitor AV for us from SEP.
So, My question is..
1. Where can I get syslog format?
2. Where can I get Windows Event ID for AV monitor?
Thank you in advance for any assistance.