Chapter_12_Forwarding Flashcards
1
Q
What can be forwarded via email?
A
Only Alerts can be forwarded via email
2
Q
How can other information be forwarded?
A
Other information (as well as alerts) may be forwarded via Syslog
3
Q
Why might you configure forwarding conditions?
A
So Alerts get sent not only to the SEIM and SOC, but also to the Operations center managing the OT device
4
Q
What format are Syslog messages sent using? Can the message be edited? If so, how?
A
CEF, LEEF and JSON(Splunk) are the standard formats, but they can be edited by adding any available tag from the SilentDefense properties database.