Go to the table of contents Go to the previous page Go to the next page
TRITON RiskVision System Management : RiskVision SIEM/syslog format strings
RiskVision SIEM/syslog format strings
System Management | TRITON RiskVision | 02-June-2016
The string used to format data sent to syslog or a third-party SIEM product may include any of several keys, listed in the table below. Each key appears as follows in the format string:
%<key_name>
Key names are case sensitive.
*
*
%<\n>
Event priority
The first field in the SIEM or syslog format string is used to specify the event priority (PRI).
The priority is calculated for each event based on a combination of severity and risk scores reported by the analytic tools used to determine that a security incident occurred.
The higher the number, the more factors indicate a high severity incident.
Keys
The keys that can be included in records sent to SIEM or syslog are:

Go to the table of contents Go to the previous page Go to the next page
TRITON RiskVision System Management : RiskVision SIEM/syslog format strings
Copyright 2016 Forcepoint LLC. All rights reserved.