<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Imperva CEF not parsing header in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505062#M2049</link>
    <description>&lt;P&gt;yes, this is the message in the configuration in the imperva box.&lt;/P&gt;&lt;P&gt;I will search and validate the configuration in the imperva and I will notify you. Thanks a lot&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2020 18:28:15 GMT</pubDate>
    <dc:creator>joelggoti</dc:creator>
    <dc:date>2020-06-18T18:28:15Z</dc:date>
    <item>
      <title>Imperva CEF not parsing header</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505026#M2039</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MicrosoftTeams-image (1).png" style="width: 921px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9238i88AE63401D0D0ABB/image-size/large?v=v2&amp;amp;px=999" role="button" title="MicrosoftTeams-image (1).png" alt="MicrosoftTeams-image (1).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hi,&amp;nbsp;we have trouble seeing the data, sent by syslog in format cef, from the imperva to splunk.&amp;nbsp;we have&amp;nbsp;&lt;SPAN&gt;Splunk Add-on for Imperva SecureSphere WAF&lt;/SPAN&gt; installed.&lt;/P&gt;&lt;P&gt;thanks for your quick response,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 16:14:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505026#M2039</guid>
      <dc:creator>joelggoti</dc:creator>
      <dc:date>2020-06-18T16:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Imperva CEF not parsing header</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505032#M2040</link>
      <description>Did you install the Imperva add-on on both the indexer(s)/HF(s) AND the search heads?</description>
      <pubDate>Thu, 18 Jun 2020 16:51:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505032#M2040</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-18T16:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Imperva CEF not parsing header</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505035#M2041</link>
      <description>&lt;P&gt;Thanks for answering, we have a single instance and everything is installed.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 16:57:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505035#M2041</guid>
      <dc:creator>joelggoti</dc:creator>
      <dc:date>2020-06-18T16:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Imperva CEF not parsing header</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505040#M2043</link>
      <description>&lt;P&gt;The mangled part of the log event is the syslog header, the part that has the timestamp host/ip etc, something like the below googled sample:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class="pln"&gt;&amp;lt;34&amp;gt;1 2003-10-11T22:14:15.003Z mymachine.example.com &lt;STRONG&gt;&lt;EM&gt;cef stuff here&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;I think if you take a look at your syslog configuration on Imperva and any intermediary systems supporting your syslog transport you should be able to find the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- upvotes appreciated&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":nerd_face:"&gt;🤓&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 17:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505040#M2043</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2020-06-18T17:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Imperva CEF not parsing header</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505045#M2044</link>
      <description>Is there a setting in Imperva where the binary data in the CEF events can be removed?</description>
      <pubDate>Thu, 18 Jun 2020 17:30:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505045#M2044</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-18T17:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Imperva CEF not parsing header</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505056#M2046</link>
      <description>&lt;P&gt;i use this message:&lt;/P&gt;&lt;P&gt;CEF:0|Imperva Inc.|SecureSphere|[SecureSphere version #] |${Alert.alertType}|${Alert.alertMetadata.alertName}|${Alert.severity}|act=${Alert.immediateAction} dst=${Event.destInfo.serverIp} dpt=${Event.destInfo.serverPort} duser=${Alert.username} src=${Event.sourceInfo.sourceIp} spt=${Event.sourceInfo.sourcePort} proto=${Event.sourceInfo.ipProtocol} rt=#arcsightDate (${Alert.createTime}) cat=Alert cs1=${Rule.parent.displayName} cs1Label=Policy cs2=${Alert.serverGroupName} cs2Label=ServerGroup cs3=${Alert.serviceName} cs3Label=ServiceName cs4=${Alert.applicationName} cs4Label=ApplicationName cs5=${Alert.description} cs5Label=Description&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 18:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505056#M2046</guid>
      <dc:creator>joelggoti</dc:creator>
      <dc:date>2020-06-18T18:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Imperva CEF not parsing header</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505058#M2047</link>
      <description>&lt;P&gt;this is the configuration in Imperva correct?&amp;nbsp; webUI or something?&amp;nbsp; where is it getting sent to?&amp;nbsp; is this a blackbox Imperva installation or are you running on your own *nix server?&amp;nbsp; the syslog that is transporting this data is somehow getting a binary version of the header instead of the raw text.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what you have there is the payload, but you need to find the syslog configuration itself and validate the implementation along every link in the chain between Imperva config to Splunk input.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 18:19:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505058#M2047</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2020-06-18T18:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Imperva CEF not parsing header</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505062#M2049</link>
      <description>&lt;P&gt;yes, this is the message in the configuration in the imperva box.&lt;/P&gt;&lt;P&gt;I will search and validate the configuration in the imperva and I will notify you. Thanks a lot&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 18:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Imperva-CEF-not-parsing-header/m-p/505062#M2049</guid>
      <dc:creator>joelggoti</dc:creator>
      <dc:date>2020-06-18T18:28:15Z</dc:date>
    </item>
  </channel>
</rss>

