<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How is the record “&amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt; sent to the SITE ENGINE and then to SIEM in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-is-the-record-lt-noti-fbd-maclocking-firstarrvlrmtexcd-gt/m-p/94509#M21734</link>
    <description>&lt;P&gt;How the record “&amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt; is sent to the SITE ENGINE and then to another SIEM server (QRADAR)&lt;/P&gt;&lt;P&gt;Dear greetings:&lt;/P&gt;&lt;P&gt;I am trying to send the “&amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt;” alert to the SITE ENGINE and then from the SITE ENGINE to send only that notification to a SIEM QRADAR server.&lt;/P&gt;&lt;P&gt;The switches are linked in the "SITE ENGINE" and the LOGs generated by the switches are being recorded.&lt;/P&gt;&lt;P&gt;The switches have “mac-locking log rape” enabled and the notification appears in the log“ “&amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt; MAC address XX:XX:XX:XX:XX:XX not learned on port 2 :11 since the Mac address learning limit has been exceeded”, so far everything is fine from the switch.&lt;/P&gt;&lt;P&gt;But in the "SITE ENGINE" the notification does not appear. So, is there any additional configuration required in SITE ENGINE or switch for &amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt; logging?&lt;/P&gt;&lt;P&gt;And after solving that in the SITE ENGINE. How should that log be sent to another SIEM server?&lt;/P&gt;&lt;P&gt;I saw in the SITE ENGINE manual several options from creating alerts, another way is to create notifications or create events? But how should I select which LOG is the one I want to send to the SIEM?&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 15:48:01 GMT</pubDate>
    <dc:creator>Gago626</dc:creator>
    <dc:date>2023-01-25T15:48:01Z</dc:date>
    <item>
      <title>How is the record “&lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&gt; sent to the SITE ENGINE and then to SIEM</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-is-the-record-lt-noti-fbd-maclocking-firstarrvlrmtexcd-gt/m-p/94509#M21734</link>
      <description>&lt;P&gt;How the record “&amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt; is sent to the SITE ENGINE and then to another SIEM server (QRADAR)&lt;/P&gt;&lt;P&gt;Dear greetings:&lt;/P&gt;&lt;P&gt;I am trying to send the “&amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt;” alert to the SITE ENGINE and then from the SITE ENGINE to send only that notification to a SIEM QRADAR server.&lt;/P&gt;&lt;P&gt;The switches are linked in the "SITE ENGINE" and the LOGs generated by the switches are being recorded.&lt;/P&gt;&lt;P&gt;The switches have “mac-locking log rape” enabled and the notification appears in the log“ “&amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt; MAC address XX:XX:XX:XX:XX:XX not learned on port 2 :11 since the Mac address learning limit has been exceeded”, so far everything is fine from the switch.&lt;/P&gt;&lt;P&gt;But in the "SITE ENGINE" the notification does not appear. So, is there any additional configuration required in SITE ENGINE or switch for &amp;lt;Noti:FBD.MAClocking.FirstArrvLrmtExcd&amp;gt; logging?&lt;/P&gt;&lt;P&gt;And after solving that in the SITE ENGINE. How should that log be sent to another SIEM server?&lt;/P&gt;&lt;P&gt;I saw in the SITE ENGINE manual several options from creating alerts, another way is to create notifications or create events? But how should I select which LOG is the one I want to send to the SIEM?&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 15:48:01 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/how-is-the-record-lt-noti-fbd-maclocking-firstarrvlrmtexcd-gt/m-p/94509#M21734</guid>
      <dc:creator>Gago626</dc:creator>
      <dc:date>2023-01-25T15:48:01Z</dc:date>
    </item>
  </channel>
</rss>

