cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cdyk
Level 7
Report Inappropriate Content
Message 1 of 5

Rule message or Event name showing as "0" for DataSources.

Hi guys,

When i check the SIEM,I found that the event name/the rule message is replaced with "0".

I want to understand more about this Please help me out.

Please find below the screenshot.

Thanks in advance.

4 Replies
acommons
Level 11
Report Inappropriate Content
Message 2 of 5

Re: Rule message or Event name showing as "0" for DataSources.

This can happen after rules have been deleted. The events associated with those rules appear with the '0' as the message.

I have also seen this as a side effect of deleting rules where events that were not impacted by the rule deletion, i.e. their rules were not deleted, also show up as '0'. In this case it corrected itself as  messages for the rules were subsequently parsed as new events arrived.

Hope that helps.

cdyk
Level 7
Report Inappropriate Content
Message 3 of 5

Re: Rule message or Event name showing as "0" for DataSources.

But on a specific Data Source.

"Support generic syslogs" field is set to "parse as generic syslog".

Can this also be a reason?

acommons
Level 11
Report Inappropriate Content
Message 4 of 5

Re: Rule message or Event name showing as "0" for DataSources.

If you start to clean up the auto-generated rules then yes this can be the reason. The approach I take is to first delete the ESM events associated with the auto-learned rules and then delete the auto-learned rules themselves. You can still get the transient '0' rule messages but, in my experience, they clean themselves up.

xded
Level 12
Report Inappropriate Content
Message 5 of 5

Re: Rule message or Event name showing as "0" for DataSources.

Hi cdyk,

no this is not the reason for the 0 description.

This will only happens if you delete a  autolearned rule or a Correlation rule and in special times if you delete Parser rules.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community