This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
      • Netwitness XDR
      • EC-Council Training
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
    • Role-Based Training
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Re: Menlo Security Custom Log Parser - Opinion Sought
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Menlo Security Custom Log Parser - Opinion Sought

JeremyKerwin
JeremyKerwin Valued Contributor
Valued Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2021-02-01 10:24 PM

We use Menlo Security platform for our web proxy and have built a custom lua parser to process the CEF based logs. (Menlo allows for QRadar and Splunk formatted logs but we chose CEF)

 

We're not entirely sure that it's properly working or if what we did is the best performance for NetWitness.

 

I've attached the parser and a sample log file, I was wondering if someone with more experience in writing log parser could look over it and see if there are any improvements we could make or if the way we took wasn't the correct one.

 

Thanks. 

  • Community Thread
  • Discussion
  • Forum Thread
  • NetWitness
  • NW
  • NWP
  • RSA NetWitness
  • RSA NetWitness Platform
menlo.txt.zip
menlo_security_msip.zip
0 Likes
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
4 REPLIES 4

DaveGlover
Trusted Contributor DaveGlover Trusted Contributor
Trusted Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2021-02-01 10:46 PM

Jeremy 

 

I will take a look at what you have.  However my $.02 I would use the LEEF (qradar) over CEF.  The format is so much easier to work with.

 

Dave

0 Likes
Reply

JeremyKerwin
JeremyKerwin Valued Contributor
Valued Contributor
In response to DaveGlover
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2021-02-01 10:48 PM

Thanks Dave, I appreciate the help. 

0 Likes
Reply

DaveGlover
Trusted Contributor DaveGlover Trusted Contributor
Trusted Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2021-02-01 10:50 PM

Jeremy I just looked this over and I can not get it to work at all.  Is the default CEF parser not parsing this device at all?

 

Are you putting the entire message into "msghold"?

 

content="<param_event_time><msghold>"/>

0 Likes
Reply

JeremyKerwin
JeremyKerwin Valued Contributor
Valued Contributor
In response to DaveGlover
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Report Inappropriate Content

‎2022-02-14 04:08 AM

Hi Dave, sorry for the almost year delay, must've lost track of this one.

I think you're correct. I didn't write the original parser, however I think the intent was in the log file there are fields on sessions and browser ids so the goal was to match those together and I don't think the CEF parser won't processing it properly.

0 Likes
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.