Forum Discussion

shamed's avatar
shamed
Copper Contributor
Apr 29, 2023
Solved

AMA agent in linux not sending syslog events

We have installed a Linux machine with AMA agent. We have configured DCR at CEF connector page to ingest CEF logs.   While i notice CEF logs are being ingested to Sentinel (CommonSecurityEvent) tab...
  • LucasTrainer's avatar
    Apr 30, 2023
    It sounds like you might need a second DCR to collect the Syslog events. One DCR will collect CEF, and the second Syslog.

Resources