cancel
Showing results for 
Search instead for 
Did you mean: 
fcb
Level 7
Report Inappropriate Content
Message 1 of 5

Syslog xml parsing template with Logstash

Hi All,

We are trying to use the functionality of the syslog registered server from ePO 5.9. However, the only way the files are received is via xml, which would be fine, but McAfee xml files are nested beyond infinity. Has anybody attempted this before? We have logged numerous calls with McAfee, but they just say that their job is done. The files are sent to the syslog server, what we do with it and what we need to do to parse these is our own problem.

4 Replies
Reliable Contributor Peacekeeper
Reliable Contributor
Report Inappropriate Content
Message 2 of 5

Re: Syslog xml parsing template with Logstash

Moved to EPO forum

Highlighted

Re: Syslog xml parsing template with Logstash

This is incredibly unhelpful, but we were pulling events from ePO via database scraping when they released syslog support.    We looked at their syslog, and it was not a better choice than database scraping, for the reasons you mentioned.  The implementation felt like checking the marketing box, "Yes, we do support syslog!".  It just isn't in a format that's usable.

fcb
Level 7
Report Inappropriate Content
Message 4 of 5

Re: Syslog xml parsing template with Logstash

Yeah, Shocking. We have been using db scraping as well, but every time a product update or ePO update is released, all the queries need to be reconfigured. Not really helpful.

Re: Syslog xml parsing template with Logstash

That was a concern for us, too.  We thought about trying to parse the syslog for exactly that reason...and then we realized that the syslog output was as likely to change format as the underlying DB.  Probably more likely, since it was a new feature. 

More McAfee Tools to Help You

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community