Remote devices must be configured with a new receiver to accept the rsyslog feed from Carbon Black EDR.
Whether the remote device is an instance of SPLUNK, ArcSight, or another manager-of-managers platform such as Tivoli, the basic setup requirements are the same.
Note:
The procedure for setting up remote devices differs depending upon the device itself. The basics are described here. Adapt the procedure to your particular platform.