What can be forwarded via email?
Only Alerts can be forwarded via email
How can other information be forwarded?
Other information (as well as alerts) may be forwarded via Syslog
Why might you configure forwarding conditions?
So Alerts get sent not only to the SEIM and SOC, but also to the Operations center managing the OT device
What format are Syslog messages sent using? Can the message be edited? If so, how?
CEF, LEEF and JSON(Splunk) are the standard formats, but they can be edited by adding any available tag from the SilentDefense properties database.