I'm having trouble with Mcafee SIEM log collection.
The idea is to collect the data from Oracle DB to the ESM using McAfee SIEM Collector Management Utility.
The client on the collector, and the data source on the ESM receiver are shown on the picture below.
Now the problem is that the logs are being duplicated (multiple events from the same raw packet), not for all data and not with any evident pattern.
Has anyone run into the same/similar problem?
I assume it's because of the Bookmark you have set for SISTEM column. Don't you have a column with an incremental number you could use ?
Thanks for your reply.
My bet is also on the bookmark because when I tried to use a field like date/time I don't get any data at all.
I don't have the strictly incremental field, but I'll try to create something, and get back to you