Azure-Sentinel/DataConnectors/CEF
Noam Landress d26dce3016 add OMI check for version 1.17.2 2023-11-12 12:57:17 +02:00
..
README.md Add read me file 2019-07-23 17:22:38 +03:00
TimeGenerated.py update error message 2020-11-23 15:40:28 +02:00
cef_gather_info.py Feature/noamlandress/update os list for cef (#4273) 2022-02-27 18:04:02 +02:00
cef_installer.py Handle -d argument to set other oms domains (#7573) 2023-03-15 14:06:41 +02:00
cef_troubleshoot.py add OMI check for version 1.17.2 2023-11-12 12:57:17 +02:00

README.md

Common Event Format

Common Event Format (CEF) is an industry standard format on top of Syslog messages, used by many security vendors to allow event interoperability among different platforms. By connecting your CEF logs to Azure Sentinel, you can take advantage of search & correlation, alerting, and threat intelligence enrichment for each log.

CEF Scripts

The scripts found under this directory would be used to install the CEF agent on any Linux machine having rsyslog or syslog-ng.