If you have any questions, please contact: aha.support@ts.fujitsu.com
The ISM server should send sits own* audit log to a syslog server or forwarding to ArcSight SIEM Server.
*"own" means: I.e. only the actions that a user has made on the ISM server via GUI or CLI should be forwarded. So not the event logs of the monitored servers.
A syslog server is running but nor configurable:
# ismadm service show
UNIT FILE STATE
rsyslog.service enabled
Thank you Wolfgang Brehm for this idea and your additional comments.
It looks like you have found a workaround solution. So we will close this idea.
It can be closed.
We find a solution.
Define Action Type: Forward Syslog and assign it to a system alaram.