Hello everyone
I have an issue with a datasource, the device is sending logs in CEF format and is logging the events but the SIEM only grabs the basic fields and there are more fields that I would like to view. For example the event only has IP, Port, action and host. But In the log I have Interface, Profile, Category, Vlan, etc..
Does anyone knows how can I add these extra fields to the event, is it with custom parsing?
Solved! Go to Solution.
Yes.
use the ASP - Advanced Syslog Parser Interface.
if you need help with the REGEX just upload here
the "test text \ packet text"
and the REGEX you are trying to write.
i and the entire wonderful community will try helping out.
Best Regards👍👍👍
David.
Yes.
use the ASP - Advanced Syslog Parser Interface.
if you need help with the REGEX just upload here
the "test text \ packet text"
and the REGEX you are trying to write.
i and the entire wonderful community will try helping out.
Best Regards👍👍👍
David.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA