We are currently working on collecting the logs from McAfee EPO (without pooling the database ) using the agent as the syslog server .
In the EPO we can configure a syslog server to send our events , in that case the syslog server is our agent
We try some configuration but still not working
Keep time, host, source, sourcetype, event, classification, os, dc, severity, module, stanza, collector_hostname, collector_received_at
$source = "mcafee_epo";
log_info("event : " +$event);
Path i_mcafee_epo_raw => onul
I was wondering I we need to use the module xm_syslog as the module