Forward alerts to the SIEM you already run — RFC5424 or CEF, no cloud.
Where to get it
Your existing syslog collector / SIEM — Splunk, Elastic, Graylog, Wazuh itself.
Install / what you need
No install. You need the collector host + port (UDP/TCP/TLS).
How to connect
- 1 Point CyberCLI at your syslog/SIEM collector (host, port, transport).
- 2 Open the dashboard's Notifications panel → Add destination → choose syslog (pick RFC5424 or CEF format).
- 3 Confirm events arrive in your SIEM index.
When you'd use it
"Notify the SIEM I already have" without any cloud hop.
Feed correlation rules downstream.
MSP stack integration.
Sovereignty
A direct forward to your collector on your network — the most SOC-native, cloud-free egress.
Who notifies through it
Herald — the Guild's voice role — routes alerts, daily digests, and AI verdicts here, on a per-CYCON-state matrix you control. CYCON 1/2 alerts repeat until an operator acks.
The Guild →