Intel Security SNS ProTip for SIEM: ASP rules enabled in the Default Policy causes parsing issues on the Receiver

Version 1

    On occasion, the SIEM Event Receiver may behave unexpectedly or becomes unresponsive after enabling ASP Rules in the Default Policy and individual data sources stop parsing. In some cases, complete parsing failure on the Receiver might occur. This is because ASP Rules are not designed to be enabled at the Default Policy level. They are only meant to be enabled at the Data Source/Parent level.


    For information on how to solve this issue, see KB84620 (


    For more resources, visit the ServicePortal [] and search for related content. Also, visit the McAfee SIEM Community (


    SNS ProTips help you maximize your protection with troubleshooting, best practices, how-to tips, and links to Knowledge Center resources. To unsubscribe from ProTips or change your SNS settings, visit the SNS Subscription Center.