Which plug-in is used by the Cloud Pak for Data Audit Logging service to forward audit records to a SIEM system?
The Audit Logging service in IBM Cloud Pak for Data uses Fluentd as the core log forwarding mechanism. Fluentd output plug-ins are configured to route audit logs to external SIEM systems such as Splunk or QRadar. These plug-ins are versatile and support multiple formats and transport protocols. Other options listed---like Logstash, OSS/J, or Kafka---are not the designated default forwarding mechanisms used within the CP4D Audit Logging architecture.
Currently there are no comments in this discussion, be the first to comment!