Forum Discussion
shamed
Apr 29, 2023Copper Contributor
AMA agent in linux not sending syslog events
We have installed a Linux machine with AMA agent. We have configured DCR at CEF connector page to ingest CEF logs. While i notice CEF logs are being ingested to Sentinel (CommonSecurityEvent) tab...
- Apr 30, 2023It sounds like you might need a second DCR to collect the Syslog events. One DCR will collect CEF, and the second Syslog.
LucasTrainer
Apr 30, 2023Copper Contributor
It sounds like you might need a second DCR to collect the Syslog events. One DCR will collect CEF, and the second Syslog.
shamed
May 05, 2023Copper Contributor
This is right. I just looked at the DCR for CEF, it was sending the logs to CommonSecurityLog. Hence why the Syslog table was empty. Had to create another DCR