4 Replies Latest reply on Aug 28, 2017 8:48 AM by ksudki

    Autolearn Windows datasources forwarded by syslog


      Dear community,


      I want to automatically create Windows Data Sources for non windows native events (DNS/DHCP/IIS/...). For this, I want to use the "auto learn" feature with the logs being forwarded to the receiver using syslog.


      On the ESM, I can see the data source but no type is detected which is indeed a problem.


      Is there any known limitations to do this? (I already tested this without success McAfee Corporate KB - The SIEM autolearn feature fails to work KB82128 )