Hi all,
I'm writing some custom parsers for couple of my devices which are connected to my ESM Combo appliance, and I have a strange thing happening. After I develop the parser, I start a live capture for the given device and generate some logs. I can see that the parser rule is triggered because the rule name appears in the associated live capture column. However, when I go to the Normalized Dashboard for the given device I cannot see any of the events which I have triggered. Have some of you had something similar happen? I don't know what I'm missing. Any suggestions on how to troubleshoot this will be much appreciated.
Thank you!
Kind regards,
Blagoja