- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sentinelone Parser
Hi,
I get logs from Sentinelone with syslog and the previously parsed logs do not parser, it hits a different parser. Fortinet has a default parser and when I examine the documentation, it should parser in CEF format. Has anyone encountered this situation?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you expand on this?
You have SentinelOne logs via syslog and after an upgrade they no longer parse?
What is the Event Parser that is matching these events?
Are they still in CEF format?
Is old message header vs new message header different?
Created on ‎07-10-2024 12:02 AM Edited on ‎07-10-2024 12:29 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can't see a CEF in the log right now. When I checked the old logs, they were also in unknown status.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Does anyone have a parser in Json format related to SentinelOne?
