I'm working on a project in which we are implementing CA PAM 3.3.1 and integrating with ArcSite for SysLog purposes.
The syslog admin has raised the following question: "We are getting data in CSV format which is not supported by the SIEM solution (ArcSight). Log format should be in CEF. Can you change the log format to CEF from CSV?"
Also, regarding the syslog server configuration, when multiple syslog servers are specified with a delimiting '|' is the second syslog server a backup/failover reference or is data duplicated to both nodes concurrently?
thanks in advance.
------------------------------
Services Architect
HCL Technologies Ltd
------------------------------