Structure of events2logger.yml

Modified on Tue, Jun 15, 2021 at 2:11 PM

The events2logger.yml file configures how and where events are retrieved and forwarded. An example file is attached.


Global Settings

api.url
URL to the 802 Secure API Console - must be https://api.802secure.net/apiv1/customer
api.key
An API Key from here
sleep
Time between checks for new events in seconds
exclude_source
Sources to exclude when retrieving
include_sources
Sources to only include when retrieving
minimum_severity
Minimum severity level to retrieve
output_format
Global message output format: json, cef or undefined. Will be overridden by destination settings.

Syslog Settings

server
Target server DNS or IP Address
proto
Protocol to use: udp, tcp, tcp+tls
port
Target port to connect to
output_format
Format for messages: json or cef
facility
Syslog facility to use, e.g. LOG_LOCAL5
certificate
If using tcp+tls the PEM formatted file of the server's public certificate.
tag
Additional tag to include

Graylog Settings

server
Target server DNS or IP Address
port
Target port to connect to

Slack Settings

webhook
Your Slack webhook
channel
Target channel to deliver messages to
emoji
A Slack icon-emoji to use, e.g. :ghost:

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article