<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk_TA_mcafee-wg fields wrong? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447041#M55003</link>
    <description>&lt;P&gt;Is it me or are the extractions in Splunk_TA_mcafee-wg next to totaly wrong?&lt;/P&gt;

&lt;P&gt;To take an example Log entry from some of my activity the log looks like this:&lt;/P&gt;

&lt;P&gt;Jul 18 08:44:27 xxx_hostname_xxx mwg: McAfeeWG|time_stamp=[18/Jul/2018:08:44:27 +0200]|auth_user=cn=XXXX,ou=XXX,ou=XXXX,ou=XXX,o=XXX|src_ip=10.9.16.6|server_ip=172.217.22.100|host=&lt;A href="http://www.google.com%7Curl_port=443%7Cstatus_code=200%7Cbytes_from_client=958%7Cbytes_to_client=426%7Ccategories=Search" target="_blank"&gt;www.google.com|url_port=443|status_code=200|bytes_from_client=958|bytes_to_client=426|categories=Search&lt;/A&gt; Engines|rep_level=Minimal Risk|method=GET|url=&lt;A href="https://www.google.com/searchdomaincheck?format=domain&amp;amp;type=chrome%7Cmedia_type=text/plain%7Capplication_name=Google%7Cuser_agent=Mozilla/5.0" target="_blank"&gt;https://www.google.com/searchdomaincheck?format=domain&amp;amp;type=chrome|media_type=text/plain|application_name=Google|user_agent=Mozilla/5.0&lt;/A&gt; (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.79 Safari/537.36|referer=|block_res=0|block_reason=|virus_name=|hash=|filename=searchdomaincheck|filesize=426|&lt;/P&gt;

&lt;P&gt;for src, src_ip,user,user_agent the value is  "unknown"&lt;/P&gt;

&lt;P&gt;There is the field auth_user containing the dn but i think user should contain the cn...&lt;/P&gt;

&lt;P&gt;What am i doing wrong?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 20:30:36 GMT</pubDate>
    <dc:creator>dominiquevocat</dc:creator>
    <dc:date>2020-09-29T20:30:36Z</dc:date>
    <item>
      <title>Splunk_TA_mcafee-wg fields wrong?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447041#M55003</link>
      <description>&lt;P&gt;Is it me or are the extractions in Splunk_TA_mcafee-wg next to totaly wrong?&lt;/P&gt;

&lt;P&gt;To take an example Log entry from some of my activity the log looks like this:&lt;/P&gt;

&lt;P&gt;Jul 18 08:44:27 xxx_hostname_xxx mwg: McAfeeWG|time_stamp=[18/Jul/2018:08:44:27 +0200]|auth_user=cn=XXXX,ou=XXX,ou=XXXX,ou=XXX,o=XXX|src_ip=10.9.16.6|server_ip=172.217.22.100|host=&lt;A href="http://www.google.com%7Curl_port=443%7Cstatus_code=200%7Cbytes_from_client=958%7Cbytes_to_client=426%7Ccategories=Search" target="_blank"&gt;www.google.com|url_port=443|status_code=200|bytes_from_client=958|bytes_to_client=426|categories=Search&lt;/A&gt; Engines|rep_level=Minimal Risk|method=GET|url=&lt;A href="https://www.google.com/searchdomaincheck?format=domain&amp;amp;type=chrome%7Cmedia_type=text/plain%7Capplication_name=Google%7Cuser_agent=Mozilla/5.0" target="_blank"&gt;https://www.google.com/searchdomaincheck?format=domain&amp;amp;type=chrome|media_type=text/plain|application_name=Google|user_agent=Mozilla/5.0&lt;/A&gt; (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.79 Safari/537.36|referer=|block_res=0|block_reason=|virus_name=|hash=|filename=searchdomaincheck|filesize=426|&lt;/P&gt;

&lt;P&gt;for src, src_ip,user,user_agent the value is  "unknown"&lt;/P&gt;

&lt;P&gt;There is the field auth_user containing the dn but i think user should contain the cn...&lt;/P&gt;

&lt;P&gt;What am i doing wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:30:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447041#M55003</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2020-09-29T20:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_mcafee-wg fields wrong?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447042#M55004</link>
      <description>&lt;P&gt;Hi dominiquevocat, did you found a solution to your problem?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 14:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447042#M55004</guid>
      <dc:creator>jbrocks</dc:creator>
      <dc:date>2018-08-01T14:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_mcafee-wg fields wrong?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447043#M55005</link>
      <description>&lt;P&gt;Hello, can you paste your props.conf and transforms.conf from Splunk_TA_mcafee-wg/default OR local. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:46:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447043#M55005</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2020-09-29T20:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_mcafee-wg fields wrong?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447044#M55006</link>
      <description>&lt;P&gt;nope, we opened a support ticket and have a enhancement request going&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 07:30:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447044#M55006</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2018-08-03T07:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_mcafee-wg fields wrong?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447045#M55007</link>
      <description>&lt;P&gt;hi, we use the TA out of the box - we have a newer version of mcafee web gateway then is supported by the TA&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 07:31:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447045#M55007</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2018-08-03T07:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_mcafee-wg fields wrong?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447046#M55008</link>
      <description>&lt;P&gt;I am not sure if this will help you, but I think the MWG AddOn only works with syslog. So you need to import a .xml file to MWG which helps splunk decoding the headers and parsing the right fields. As far as i understood this article: &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/McAfeeWG/Setup"&gt;https://docs.splunk.com/Documentation/AddOns/released/McAfeeWG/Setup&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/138800/import-log-file.html"&gt;https://answers.splunk.com/answers/138800/import-log-file.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2018 10:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447046#M55008</guid>
      <dc:creator>jbrocks</dc:creator>
      <dc:date>2018-08-03T10:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_mcafee-wg fields wrong?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447047#M55009</link>
      <description>&lt;P&gt;@dominiquevocat @jbrocks Did either of you ever get a solution to this? I appear to have the same problem.&lt;/P&gt;

&lt;P&gt;As far as I'm aware we are also using the TA as it was downloaded and no changes were made to props or transforms files.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 21:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447047#M55009</guid>
      <dc:creator>pkellyz</dc:creator>
      <dc:date>2020-01-14T21:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_mcafee-wg fields wrong?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447048#M55010</link>
      <description>&lt;P&gt;no update on the enhancement request -  i m not sure if we tried to fix it ourselfs&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2020 12:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-mcafee-wg-fields-wrong/m-p/447048#M55010</guid>
      <dc:creator>dominiquevocat</dc:creator>
      <dc:date>2020-01-24T12:31:39Z</dc:date>
    </item>
  </channel>
</rss>

