I need a solution
I am implementing SSIM to replace another SIEM product. Currently most of the products use syslog to send logs. Is it possible to retain the same architecture or do I need to install the specific agents on each of the products? What is lost if the syslog protocol is retained?