<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eNcore eStreamer 3.6.1 fieldalias not being applied in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503436#M61992</link>
    <description>&lt;P&gt;@douglashurd Does the 3.6.x fixed version also include the missing eventtypes and tags that I mentioned in this &lt;A href="https://answers.splunk.com/answers/776174/latest-estreamer-not-cim-compliant.html#answer-776248"&gt;question&lt;/A&gt;?&lt;/P&gt;</description>
    <pubDate>Mon, 14 Oct 2019 18:08:02 GMT</pubDate>
    <dc:creator>bmorgenthaler</dc:creator>
    <dc:date>2019-10-14T18:08:02Z</dc:date>
    <item>
      <title>eNcore eStreamer 3.6.1 fieldalias not being applied</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503434#M61990</link>
      <description>&lt;P&gt;Deploying eNcore eStreamer 3.6.1 I have found that the field alias for intrusion signatures is not being applied in my searches:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk cmd btool props list cisco:estreamer:data | grep ALIAS
...
FIELDALIAS-estreamer_intrusion_signature = msg AS signature
FIELDALIAS-estreamer_severity = priority AS severity
FIELDALIAS-estreamer_src = src_ip AS src
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Attached is a screenshot for one event, you can see that src and severity are there, but there is no signature. Without the fieldalias, anything in the Intrusion Data Model has unknown for the signature of the attack in it.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7823iD9B417C408C39DF1/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 20:00:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503434#M61990</guid>
      <dc:creator>bmorgenthaler</dc:creator>
      <dc:date>2019-10-11T20:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: eNcore eStreamer 3.6.1 fieldalias not being applied</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503435#M61991</link>
      <description>&lt;P&gt;3.6.1 has a bug that we discovered on 10/11.  We changed default download to 3.5.8.  There will be a 3.6.x posted in a few days that will fix the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 17:54:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503435#M61991</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2019-10-14T17:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: eNcore eStreamer 3.6.1 fieldalias not being applied</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503436#M61992</link>
      <description>&lt;P&gt;@douglashurd Does the 3.6.x fixed version also include the missing eventtypes and tags that I mentioned in this &lt;A href="https://answers.splunk.com/answers/776174/latest-estreamer-not-cim-compliant.html#answer-776248"&gt;question&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2019 18:08:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503436#M61992</guid>
      <dc:creator>bmorgenthaler</dc:creator>
      <dc:date>2019-10-14T18:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: eNcore eStreamer 3.6.1 fieldalias not being applied</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503437#M61993</link>
      <description>&lt;P&gt;we've more recently pushed 3.6.8 with more bug fixes.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 23:05:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503437#M61993</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2019-11-15T23:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: eNcore eStreamer 3.6.1 fieldalias not being applied</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503438#M61994</link>
      <description>&lt;P&gt;This doesn't have seem to fix the field aliases.. I'm having the EXACT same problem, only seems to be having issues with signature for intrusion detection data model.&lt;/P&gt;

&lt;P&gt;Splunk version: 7.2.6&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 01:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503438#M61994</guid>
      <dc:creator>chawagon03_sti</dc:creator>
      <dc:date>2019-11-21T01:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: eNcore eStreamer 3.6.1 fieldalias not being applied</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503439#M61995</link>
      <description>&lt;P&gt;Actually I believe I have fixed the issue I'm having (signature aliases for both malware and intrusion detection data models). &lt;/P&gt;

&lt;P&gt;I've removed the FIELDALIASES that try and create the fields required, and replace it with my own in local directory...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;props.conf

[cisco:estreamer:data]
EVAL-signature = coalesce(msg,detection)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Nov 2019 02:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503439#M61995</guid>
      <dc:creator>chawagon03_sti</dc:creator>
      <dc:date>2019-11-21T02:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: eNcore eStreamer 3.6.1 fieldalias not being applied</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503440#M61996</link>
      <description>&lt;P&gt;Thanks for the update.  I'll review with our developer. &lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2019 00:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/503440#M61996</guid>
      <dc:creator>douglashurd</dc:creator>
      <dc:date>2019-11-23T00:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: eNcore eStreamer 3.6.1 fieldalias not being applied</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/549352#M65478</link>
      <description>&lt;P&gt;I got the same issue but with eStreamer 4.2 and 4.0. If you are using Splunk 7.2 or later, there is a limitation you can't use two field aliases for the same field. Take a look into signature aliase:&lt;/P&gt;&lt;P&gt;&lt;A href="http://10.201.251.180/en-GB/manager/InfoSec_App_for_Splunk/data/props/fieldaliases/cisco%3Aestreamer%3Adata%20%3A%20FIELDALIAS-estreamer_intrusion_signature?action=edit&amp;amp;ns=TA-eStreamer&amp;amp;f_ns=TA-eStreamer&amp;amp;f_pwnr=-&amp;amp;f_search=&amp;amp;f_count=100&amp;amp;uri=%2FservicesNS%2Fnobody%2FTA-eStreamer%2Fdata%2Fprops%2Ffieldaliases%2Fcisco%253Aestreamer%253Adata%2520%253A%2520FIELDALIAS-estreamer_intrusion_signature" target="_blank"&gt;cisco:estreamer:data : FIELDALIAS-estreamer_intrusion_signature&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://10.201.251.180/en-GB/manager/InfoSec_App_for_Splunk/data/props/fieldaliases/cisco%3Aestreamer%3Adata%20%3A%20FIELDALIAS-estreamer_malware_signature?action=edit&amp;amp;ns=TA-eStreamer&amp;amp;f_ns=TA-eStreamer&amp;amp;f_pwnr=-&amp;amp;f_search=&amp;amp;f_count=100&amp;amp;uri=%2FservicesNS%2Fnobody%2FTA-eStreamer%2Fdata%2Fprops%2Ffieldaliases%2Fcisco%253Aestreamer%253Adata%2520%253A%2520FIELDALIAS-estreamer_malware_signature" target="_blank"&gt;cisco:estreamer:data : FIELDALIAS-estreamer_malware_signature&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to remove the overwrite on both Field Aliases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 15:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/eNcore-eStreamer-3-6-1-fieldalias-not-being-applied/m-p/549352#M65478</guid>
      <dc:creator>drivascordero</dc:creator>
      <dc:date>2021-04-26T15:30:22Z</dc:date>
    </item>
  </channel>
</rss>

