Configuring the SIEM system on KSC10 is not enough! You need to configure the events you want to forward :
1. Open your polic[y|ies] and go to "Event Configuration" ;
2. On each Tab (Critical Event, Functional failure, Warning, Info), highlight each event you would like to have forwarded and click on the bottom right button "Properties" ;
3. On each event's Properties window, check the box "Export to SIEM system via syslog" and click OK;
4. Click OK once more to leave/update the policy.
... View more