Nozomi syslog data events and syslog messages
For customers implementing syslog, Guardian generates three types of syslog events: alerts, health, and audit.
Note:
As the set of alert messages inside each alert type ID category
increases over time, perform searches on alert type IDs, health type IDs, and audit type
IDs, rather than on the alert message itself.