This procedure describes how to deploy Event Source Log Parsers from Live in Security Analytics 10.x.
- From the Security Analytics menu, select Live > Search.
-
Browse Live for the Event Source Log Parsers that you need using RSA Log Device as the Resource Type.
The Event Source Log Parsers available for adding and updating display.
-
Select the Event Source Log Parsers you want to deploy.
You have the following two options when deploying Event Source Log parsers:
-
Individually. You can select one or more Event Source Log Parsers to deploy. For example:
- Or as a bundle. Choose Bundle from the Resource Types, click Search, then select the Log Parser Pack that contains all Event Source Log Parsers that Security Analytics currently supports.
-
- Deploy the Event Source Log Parsers to the appropriate Log Decoders.