4 Replies Latest reply on Aug 28, 2017 8:48 AM by ksudki

    Autolearn Windows datasources forwarded by syslog

    ksudki

      Dear community,

       

      I want to automatically create Windows Data Sources for non windows native events (DNS/DHCP/IIS/...). For this, I want to use the "auto learn" feature with the logs being forwarded to the receiver using syslog.

       

      On the ESM, I can see the data source but no type is detected which is indeed a problem.

       

      Is there any known limitations to do this? (I already tested this without success McAfee Corporate KB - The SIEM autolearn feature fails to work KB82128 )

       

      Regards