Aurora Endpoint Security syslog forwarding
You can configure Aurora Endpoint Security to forward events to a single SIEM solution or syslog server. Each event is presented as Unicode plain text in comma-separated key-value pairs.
If your organization requires events to be sent to multiple SIEM solutions or syslog servers, you can configure a syslog forwarder. For more information, see the documentation for your syslog or SIEM server.
If the Aurora Endpoint Security integration cannot successfully deliver syslog messages to a syslog or SIEM server, an email notification is sent to users with the built-in administrator role and a confirmed email address within your organization.
The integration applies these delivery limits:
- The integration disables after 400 undelivered messages.
- The integration sends the first warning email after 133 messages fail delivery.
- The integration retries each message up to 10 times before moving it to a dead-letter queue.
Due to variable delays in event reporting, do not use Aurora Endpoint Security for real-time or near-real-time monitoring.