The messages are standard syslog messages in RFC3164 format (also called legacy-syslog or BSD-syslog format). The body of the syslog message (the MESSAGE part) can be formatted as one of:
-
Common Event Format (CEF), based on the ArcSight CEF specification rev. 16, 22 July 2010
-
JavaScript Object Notation (JSON)
-
JSON-CIM format (available in SPS version 5.11 and later).