Good Day everyone.
I have an on-prem log/sme server which is receiving logs from 14 different gateways. We also use the harmony connect product and on a typical day we have between 150-200 users on it.
On the on-prem SME server, i have a daily threat report that goes out to staff, but on the harmony portal that email report will only be sent weekly - no option to change to daily. I see that there's a way to send the logs from harmony to on-prem via a generic syslog method.
If received via syslog, does anyone know if the on-prem SME will actually process these logs and report/alert on them, or will they just be viewable as generic messages in the log viewer?
TIA.