Configure Syslog Forwarding in Darktrace
Before CCE can start ingesting data from Darktrace, a Darktrace administrator with UI access must configure Darktrace to send syslog
to the CCE(Collector).
To configure syslog forwarding in Darktrace:
Log in to Darktrace interface;
Expand top left menu and select Admin, a second menu appears;
Select System Config page
In Alerting section, click on Verify Alert Settings
In JSON Syslog Alerts, set field to True
Set syslog server to CCE Server’s IP address
Set a port 514 UDP to use with the CQ event source
Set JSON Syslog TCP Alerts to True