User Tools

Site Tools


infoblox_nios_x:logging

This is an old revision of the document!


NIOS-X Logging

  • LEEF (Log Event Extended Format) — The LEEF event format is a proprietary event format, which allows hardware manufacturers and software product manufacturers to read and map device events specifically designed for IBM QRadar integration.
  • CEF (Common Event Format) — The CEF standard format is an open log management standard that simplifies log management. CEF allows third parties to create their own device schemas that are compatible with a standard thatis used industry-wide for normalizing security events.

When using “Syslog” as a destination in Data Connector, you can choose CEF or LEEF, both of which are fully compliant with RFC 5424. The headers (PRI, VERSION, TIMESTAMP, HOSTNAME, APP-NAME, PROCID, MSGID, and STRUCTURED-DATA) are added, and the date/time format is also updated.

Endpoint Logs

When users try and disable Endpoint, it is logged in CSP under Monitor > Logs > Security logs (search for b1e.utility).

infoblox_nios_x/logging.1736274282.txt.gz · Last modified: by bstafford