Question from partner:
We have a customer who collect windows eventlogs to RSA Security Analytics, they configured a very simple forward rule that will send only one type of eventlog to another system via syslog.
We are trying to add milliseconds to this eventlog , the thing is that when RSA Security Analytics gets this eventlog, it contains milliseconds, but when it send this eventlog via a forward rule it doesn't contain the milliseconds, is it doable?
Nfurze,
I'm asking around for you. Stay tuned.