
  1. In Alerting section, click on Verify Alert Settings

  2. In JSON Syslog Alerts, set field to True

  3. Set syslog server to CCE Server’s IP address

  4. Set a port 514 UDP to use with the CQ event source

  5. Set JSON Syslog TCP Alerts to True


Ref link: https://docs.rapid7.com/insightidr/darktrace/