I am integrating ISC with the company’s SIEM. It turns out that we need to monitor source and VA failure events to open an incident for the responsible team.
There is the option to monitor source and VA events through Global > System settings > System notifications.
It turns out that these notifications are sent by email. What I wanted was to collect them through the search API, which is used by the SIEM to collect events.
When I receive, for example, a “source is unhealthy” email, when evaluating the events, I do not find any event of this nature.