<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log example for Imperva SecureSphere CEF/LEEF in Security</title>
    <link>https://community.splunk.com/t5/Security/Log-example-for-Imperva-SecureSphere-CEF-LEEF/m-p/127049#M3857</link>
    <description>&lt;P&gt;Normally, I would expect KVPs in LEEF records to be separated by TABs.  There is more discussion and a sample in &lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/507704/does-splunk-recognize-leef-formatted.html"&gt;https://answers.splunk.com/answers/507704/does-splunk-recognize-leef-formatted.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jul 2018 09:20:09 GMT</pubDate>
    <dc:creator>Rob_van_Hoboken</dc:creator>
    <dc:date>2018-07-26T09:20:09Z</dc:date>
    <item>
      <title>Log example for Imperva SecureSphere CEF/LEEF</title>
      <link>https://community.splunk.com/t5/Security/Log-example-for-Imperva-SecureSphere-CEF-LEEF/m-p/127047#M3855</link>
      <description>&lt;P&gt;Hi all.&lt;BR /&gt;
I want to do a test between Imperva's SecureSphere logs and Splunk but i haven't for now a sample of the log data. Anyone have an example file (with altered information of course)? I only see standard templates like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;LEEF:1.0|Imperva|SecureSphere|10.0.0|Firewall None|Alert ID=912905|devTimeFormat=yyyy-MM-dd HH:mm:ss.S|devTime=2014-07-22 06:59:58.0|Alert type=Firewall|src=10.0.0.1|usrName=n/a|Application name=${Alert.applicationName}|Service name=${Alert.serviceName}|Alert Description=TCP - TCP Unexpected SYN|Severity=High|Simulation Mode=false|Immediate Action=None|Event ID=4238139139125767123|dst=10.0.0.2|dp=443|Server Group=securitynik_servers|Affected Application=|Affected Application (violation)=$item.alert.applicationName|HTTP Method=|HTTP Host=|Query=
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I want to see detailed examples to try regular expressions and more.&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;

&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2015 22:20:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Log-example-for-Imperva-SecureSphere-CEF-LEEF/m-p/127047#M3855</guid>
      <dc:creator>changux</dc:creator>
      <dc:date>2015-05-25T22:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Log example for Imperva SecureSphere CEF/LEEF</title>
      <link>https://community.splunk.com/t5/Security/Log-example-for-Imperva-SecureSphere-CEF-LEEF/m-p/127048#M3856</link>
      <description>&lt;P&gt;This related question answers partially my own.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://answers.splunk.com/answers/140326/cef-parsing-using-custom-field-labels-and-the-cefutils-app.html"&gt;http://answers.splunk.com/answers/140326/cef-parsing-using-custom-field-labels-and-the-cefutils-app.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2015 03:31:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Log-example-for-Imperva-SecureSphere-CEF-LEEF/m-p/127048#M3856</guid>
      <dc:creator>changux</dc:creator>
      <dc:date>2015-05-26T03:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Log example for Imperva SecureSphere CEF/LEEF</title>
      <link>https://community.splunk.com/t5/Security/Log-example-for-Imperva-SecureSphere-CEF-LEEF/m-p/127049#M3857</link>
      <description>&lt;P&gt;Normally, I would expect KVPs in LEEF records to be separated by TABs.  There is more discussion and a sample in &lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/507704/does-splunk-recognize-leef-formatted.html"&gt;https://answers.splunk.com/answers/507704/does-splunk-recognize-leef-formatted.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 09:20:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Log-example-for-Imperva-SecureSphere-CEF-LEEF/m-p/127049#M3857</guid>
      <dc:creator>Rob_van_Hoboken</dc:creator>
      <dc:date>2018-07-26T09:20:09Z</dc:date>
    </item>
  </channel>
</rss>

