Use the SysLog Alerts dialog box to configure the sending of alerts to a SysLog server.
In addition to recording events in the event log and providing audio and system tray alerts, KFSensor is able to send to an external SysLog server.
SysLog is the standard way of recording events on UNIX machines.
The syslog protocol uses the UDP protocol. This is not as reliable as TCP, but it is effective and efficient in most situations.
The Alerts section of the Concepts part of the manual describes the different alert options in more detail.
The Common Event Format (CEF) is an open log management standard that improves the interoperability of security-related information from different security and network devices and applications. CEF is the first log management standard to support a broad range of device types. CEF enables technology companies and customers to use a common event log format so that data can easily be collected and aggregated for analysis by an enterprise management system.
Log Event Extended Format (LEEF) is a log format designed for entering data onto the Qradar system.