Ability to Filter what syslog events I want to forward
I know I can enable my events to be forwarded to a remote Syslog server, but we're missing an option to filter what events will actually be sent, at the source, in this case our DES tenant.
That would be important for narrowing the data ingestion in our XDR, and also would enable us to better manage alerts and block incidents directly in MS Defender for example, in our case is only for Blocked Processes, eventId 473.
Thanks for the feedback. We will track this as a feature request.
Until source-side filtering is available in DriveLock, you should also be able to filter or discard unwanted events on the receiving SIEM/XDR side and only process the relevant event types, such as Event ID 473.