Hello there!
I'd want to send all events logged by Aanval to a SIEM, just for audit topics.
When I enable "Console Configuration > Preferences > Syslog Mirroring" it does send only Suricata/Snort events. Is it possible to send Audit events (known as "Console Event" in database), too?
Thanks,
Best regards