We have configured the firewall to forward the correlation event logs to the syslog server. We started verifying the logs in syslog server and found the logs were not matching, all are showing the same value in the syslog server "host visited know malware URL (11 time). Whereas in firewall we see random values.
In Syslog server:
Please let me know why it always shows 11 time in Syslog server rather than showing the same value as in firewall.
So I went and took a look at the logs from my environment just to verify that I'm not seeing the same thing, and at least on 9.0.9-h1 these logs are showing up in my SIEM as expected. If you take a look at the raw syslog data sent to your SIEM, do you still see a discrepancy?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!