Go to the table of contents Go to the previous page Go to the next page
TRITON RiskVision System Management : RiskVision SIEM/syslog format strings
RiskVision SIEM/syslog format strings
52041 | System Management | TRITON RiskVision | 24-Sep-2015
The string used to format data sent to syslog or a third-party SIEM product may include any of several keys, listed in the table below. Each key appears as follows in the format string:
%<key_name>
Key names are case sensitive.
*
*
%<\n>
Event priority
The first entry in the SIEM or syslog format string is a numeric value (<20> in the sample strings). This field is used to specify the event priority (PRI).
The priority is calculated for each event based on a combination of severity and risk scores reported by the analytic tools used to determine that a security incident occurred.
The higher the number, the more factors indicate a high severity incident.
Keys
The keys that can be included in records sent to SIEM or syslog are:

Go to the table of contents Go to the previous page Go to the next page
TRITON RiskVision System Management : RiskVision SIEM/syslog format strings
Copyright 2015 Raytheon | Websense. All rights reserved.