cancel
Showing results for 
Search instead for 
Did you mean: 
priyal.dhole
Level 7

In raw logs not getting some information like Dest IP or Ports

Hi Guys,

In some alarm and events we are not getting destination IPs or ports details or any other information.

So what it the issue in this? How to resolve this issue?

0 Kudos
7 Replies
Peacekeeper
Level 20

Re: In raw logs not getting some information like Dest IP or Ports

What product is this in relation to so I can move your question to a forum better suited to get an answer. I assume SIEM is that correct

0 Kudos
Peacekeeper
Level 20

Re: In raw logs not getting some information like Dest IP or Ports

Moved to SIEM as your other question is wrt SIEM

0 Kudos
xded
Level 12

Re: In raw logs not getting some information like Dest IP or Ports

Can you please provide a example?

0 Kudos
priyal.dhole
Level 7

Re: In raw logs not getting some information like Dest IP or Ports

I am getting in destination ip like :Smiley SadDouble colon)

0 Kudos
yd9038
Level 9

Re: In raw logs not getting some information like Dest IP or Ports

The source IP and destination IP address "not-set values or aggregated values appear as "::" instead of as "0.0.0.0" in all result sets.

If there is no IP address in the event packet for receiver to parse the ESM will display that as :: instead of leaving the field blank or displaying 0.0.0.0

0 Kudos
priyal.dhole
Level 7

Re: In raw logs not getting some information like Dest IP or Ports

okey so what to do to get IP address in event packet instead of "::".

0 Kudos
xded
Level 12

Re: In raw logs not getting some information like Dest IP or Ports

Is in the Log-File a IP-Address for Destination IP or anything else? IF not you can do nothing on the parser site. If yes you can write your own parser.

Or you configure your Log on the machine and add the destination IP if is possible.

0 Kudos