1 Rookie
•
7 Posts
0
1462
March 24th, 2021 06:00
CEE & Graylog
Hello,
is possible to setup Graylog to receiving CEE audit logs?
I setup successfully a splunk endpoint with his dedicated settings but I try to do the same on Graylog with GELF HTTP but the result is always ERROR_CEPP_NOT_FOUND.
thanks
Regards
No Events found!
Rainer_EMC
4 Operator
•
8.6K Posts
0
March 25th, 2021 06:00
There are two supported ways to utilize the CEPA interface
Either the vendor works with Dell EMC engineering - than he gets its own credentials and support and can be found on the list of supported SIEM applications in the Unity ESSM
Or you configure CEPA to send the requests to RabbitMQ and then RabbitMQ as the message broker is responsible for sending to whatever application that uses them
Esprinet
1 Rookie
•
7 Posts
0
March 24th, 2021 07:00
if is not possible with Graylog we have also log insight maybe we can do with it?
sorry previously I forget to write this
Regards
DELL-Sam L
Moderator
•
7.5K Posts
0
March 24th, 2021 14:00
Hello Esprinet,
It maybe possible, but I am not seeing any steps to configure or graylog or insight.