Have you rolled out that rule?
Yep, and as you can see in the last screen shot it's generating the Signature descriptions based on the ASP rule I made.
i'm a bit perplexed
Is this parser enabled on the Default policy tab or only for this datasource?
Thank You for all your suggestions. They were very good, and I made sure to double check my self.
However, it was a simple typo that was not easy to spot.
If you notice the sample log uses two digits for year 17 not 2017. When my associate created the date mapping he used %Y instead of %y.
Once corrected all events began to appear. What's really interesting is the difference in the behavior between 9.6 an 10.X.
In 9.6 event's just disappeared.
In 10 they could only be viewed via the Events pane, the summary pane would never show any events.
I would open a ticket with McAfee but you all know how much they like to troubleshoot custom parsers, and probably would not consider this to be a issue with the engine it self.
SO it's solved every one thanks for you help.