Trying not to re-invent then wheel. Does any one have and Rules or
Reports that they configured for the Azure Event Hub Messages in the
Fortisiem. I have inlcude some basic Reports belowAzureApplicatioGatewawayAccessEventsAzureApplicatioGatewawayAcce...
Is there a way to create a pick list in a manual input that contains the
list of records returned by a the find records task.So basically I want
the user to see a list of records, and select the one that needs to be
worked with from the drop down?
Is there anyway to set up an alert if a log files has not been written
to in a set amount of time say 30 Minutes. The log files is being read
in using the User Log feature in the Windows Agent
You can pull events showing when an interface goes down and when it come
backup, However there does not appear to be a way to total the time
between the two events. Is there a way to do this. One way I have though
about, is to setup a rule that creat...
I create so many parser and try to use existing attributes:but based on
the parser these are the attributes that need to
existhostNamehostIpeventTypedeviceTimeeventActiontypecompEventTypeusrMsgstatusserverNametargetCustomereventSeveritydistinctUserms...
Sorry, I currently don't have time to help you debug it. It works fine
in my SEIM. You should try removing variables from the regex until it
works and then add them back in using the correct syntax that will match
the event
The error was probably caused by the cutting and pasting of the parser
into web form. I would check line 30 to make sure all of the variable
(hostName, srcName, userId) and pattern definitions exist in the SEIM.
And make sure the \s+ are all correct
...
Here is my PAm360 Parser, its pretty basic though
<:gPatMon>\s+<:gPatDay>\s+<:gPatTime>\s+.*ResourceAudit:|UserAudit:]]><_mon:gPatMon>\s+<_day:gPatDay>\s+<_time:gPatTime>\s+\s+<_ptype:gPatStr>::\s+<_type:gPatStr><_body:gPatMesgBody>]]>toDateTime($_mo...
Mongodb is not handled out of the box. But the parser I have above will
handle the messages in the mongodb log files. You need to update the
mongodb.conf file to send those logs to syslog and have syslog send them
to the seim. Then feel free to modif...