Configured all in accordance with article:
http://www.symantec.com/docs/TECH152638
to file syslog.conf added:
# Sending Incident Notification syslog events to another syslog server
local0.err @192.168.13.204
when the incident is created in the file /var/log/messsages appear lines, like this:
Jan 29 11:34:37 sim Incident Service[4619]: Updated incident RULE: "тестовое правило" REF: 0000002308
Jan 29 11:35:38 sim Incident Service[4619]: Created incident RULE: "тестовое правило" REF: 0000002313
but in sislog server (UDP, 514) nothing not come.
Run tcpdump on the SIM-server:
# tcpdump host 192.168.13.204
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
11:43:38.453010 arp who-has 192.168.13.204 tell sim
11:43:38.453176 arp reply 192.168.13.204 is-at 00:50:56:bc:1e:26
11:43:38.453185 IP sim.34548 > 192.168.13.204.snmptrap: V2Trap(35) system.sysUpTime.0=0 .iso.org.dod.internet=[|snmp]