Good day,
I am looking for options of exporting the audit log via an API or syslog to a SIEM solution. Currently I have the eStreamer API connected to our SIEM solution, LogRhythm. Within that API, there does not appear to be any options for monitoring account activity. I also have the syslog option configured to forward to LogRhythm. My confusion lies within the "Facility" field within the configuration.

I have been receiving the syslog, but it appears to be a limited amount of logs. I am unable to find any instance of user activity within these logs on my SIEM solution. I am specifically wanting to monitor the admin account.
When I investigate the syslog and the audit log on the SourceFire management console, I am able to find the Admin user activity. Anyone have the same issue?
Thank you