Hello community, I have an environment where the export logs in Smart Event are configured for a server in Syslog format.
However, the SIEM team informed me that the collection server is receiving 2 formats, CEF and Syslog. The CEF event is sending the same information as the other event that is in syslog format, but with a messed up header, whereas the correct information should be in each column within the SIEM tool.
I would like to understand why the collection server is receiving in CEF format if the export is configured to be in Syslog format.
The SIEM team performed a traffic capture and is only receiving traffic from Smart Event.
I consulted management and it is also exporting to the same SIEM server and in Syslog format. Does anyone have any idea why this CEF log is being sent? Is this normal behavior?