2017-01-30 12:37 PM
Has anyone developed a parser for the syslog Notifications from the Event Source / Monitoring Policies? I have been able to identify the log as an 'unknown' device type from the log collector and then generate an alert. Thanks.
Jan 30 15:22:20 localhost CEF:0|RSA|Security Analytics Event Source Monitoring|10.6.1.0| LowThresholdAlert|ThresholdViolated|1|cat=All Windows Event Source(s)|Devices| src=qtc,app007p.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app085t.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app093pb.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app196t.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app364da.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app364pb.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app409u.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app421p.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app427d.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app447ua.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app448p.prod.ds.russell.com^winevent_nic^Manual|src=qtc,app460u.prod.ds.russell.com^winevent_nic^Manual|src=qtc,db059pa.prod.ds.russell.com^winevent_nic^Manual|src=qtc,db059pb.prod.ds.russell.com^winevent_nic^Manual|src=qtc,web055p.extranet.russell.com^winevent_nic^Manual|src=qtc,web093t.prod.ds.russell.com^winevent_nic^Manual|src=qtc,web450ua.prod.ds.russell.com^winevent_nic^Manual|
2017-02-01 10:08 AM
Do you have the CEF (common event format) parser enabled and at the most recent version ?
This is required to parse the messages. I have made some small improvements to the template that hopefully bring a bit more usefulness to you (there are still some unparsed items from the string that I haven't figured out how to handle yet).
<@compress single_line=true>CEF:0|RSA|securityanalytics esm|${version}|
<#if highAlarmsCount > 0> HighThresholdAlert|ThresholdExceeded|1|cat=${group}
<#list highAlarmEventSources as es>src=${es?replace("^",",")} ;</#list>
</#if><#if lowAlarmsCount > 0> LowThresholdAlert|ThresholdViolated|1|cat=${group} |
<#list lowAlarmEventSources as es>src=${es?replace("^",",")} ;</#list>
</#if></@compress>