Custom JSON Agents
Starting with SIEM version 7.17, LogRhythm’s new Open Collection Architecture supports receiving JSON logs from any source using the Lumberjack JSON Listener on the System Monitor Agent. This enables the collection of crucial security logs from sources not natively supported by LogRhythm. Any agent using Lumberjack can be used to forward logs to the System Monitor. In the example below, a community Elastic beat, File Beat, is installed on the target collection host and used to ship logs to the System Monitor.