<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Configuring Apache Ranger to send Syslog to a SIEM system via log4j Syslog appender in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Configuring-Apache-Ranger-to-send-Syslog-to-a-SIEM-system/m-p/317112#M227015</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/42626"&gt;@ururu&lt;/a&gt;&amp;nbsp;I have a similar use case but the configurations mentioned above are not giving the desired results. Did you add or modify some of the configurations?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;E.g., I saw it being mentioned elsewhere that the hadoop.root.logger value needs to be changed as well to include SYSLOG as a value. Did you do this too?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Also, in case the external SIEM server expects a particular format, e.g., the RFC 5424 syslog format or a specific SIEM server format like Universal LEEF, what would be the best way to define this property?&lt;/P&gt;</description>
    <pubDate>Tue, 25 May 2021 14:05:02 GMT</pubDate>
    <dc:creator>CaptainJa</dc:creator>
    <dc:date>2021-05-25T14:05:02Z</dc:date>
  </channel>
</rss>

