Log forwarding of audit logs in CEF format in OCP 4
Issue
- Can OpenShift audit logs be forwarded to an external SIEM in
Common Event Format (CEF)instead of the currently supported formats? - Is it possible to use the
CEFformat for sending the audit logs? - Is
CEFsupported for audit log forwarding through OpenShift Logging? - Is it possible to use the
CEFformat for log forwarding the logs to one external SIEM system?
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Logging (RHOL)
- 5
- 6
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.