Aurora Endpoint Security syslog forwarding

You can configure Aurora Endpoint Security to forward events to a single SIEM solution or syslog server. Each event is presented as Unicode plain text in comma-separated key-value pairs.

If your organization requires events to be sent to multiple SIEM solutions or syslog servers, you can configure a syslog forwarder. For more information, see the documentation for your syslog or SIEM server.

If the Aurora Endpoint Security integration cannot successfully deliver syslog messages to a syslog or SIEM server, an email notification is sent to users with the built-in administrator role and a confirmed email address within your organization.

The integration applies these delivery limits:

  • The integration disables after 400 undelivered messages.
  • The integration sends the first warning email after 133 messages fail delivery.
  • The integration retries each message up to 10 times before moving it to a dead-letter queue.

Due to variable delays in event reporting, do not use Aurora Endpoint Security for real-time or near-real-time monitoring.