I did try collect web server access log, e.g. Apache & IIS access log, and see fields in custom type do not contain URL but only file name filled in Object field. So I did custom Apache Advacned Syslog Parser myself for this purpose.
My question is should default parser extract URL into URL field? Do I miss something?
One more question is how can I filter events on ESM with URL? There is no URL field to choose from list of filter.
Attached is my custom ASP for Apache access log.
ParinyaMessage was edited by: parinya.ekparinya on 1/10/13 5:55:21 AM CST
Sound likes a better way to collect web server log and get most information from web browsing traffic is using ADM.
Is that the recommended way to collect web browsing information for McAfee SIEM solution?
On the other hand if access log is the only thing we have, how can we get most information out of them?
For example, extract URL and User Agent will be useful information.
Another thing I just wonder is why don't we use the same custom type for URL for both event and flow?