<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Armis alerts logs parsing issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/654689#M110970</link>
    <description>&lt;P&gt;Sometimes one can tell by examining the events what changes need to be made.&amp;nbsp; In that case, go to Settings-&amp;gt;Source types, select the appropriate sourcetype, and made the needed changes.&lt;/P&gt;&lt;P&gt;Other times it's not so easy.&amp;nbsp; One approach is to export some problematic events (raw) to a file.&amp;nbsp; Get them from the original source, if possible.&amp;nbsp; Then use the Add Data wizard to upload the file and experiment with props settings until you find the combination that works.&amp;nbsp; You then can update the app as above or put the settings into an app and upload it.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Aug 2023 13:09:35 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-08-17T13:09:35Z</dc:date>
    <item>
      <title>Why are Armis alerts logs not parsing correctly?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/654657#M110961</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The Armis alerts in Splunk Cloud appear to be not being parsed correctly. We do have a technology addon for armis installed, how we can troubleshoot ??&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 18:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/654657#M110961</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-08-28T18:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Armis alerts logs parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/654689#M110970</link>
      <description>&lt;P&gt;Sometimes one can tell by examining the events what changes need to be made.&amp;nbsp; In that case, go to Settings-&amp;gt;Source types, select the appropriate sourcetype, and made the needed changes.&lt;/P&gt;&lt;P&gt;Other times it's not so easy.&amp;nbsp; One approach is to export some problematic events (raw) to a file.&amp;nbsp; Get them from the original source, if possible.&amp;nbsp; Then use the Add Data wizard to upload the file and experiment with props settings until you find the combination that works.&amp;nbsp; You then can update the app as above or put the settings into an app and upload it.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 13:09:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/654689#M110970</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-08-17T13:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Armis alerts logs parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/655777#M111104</link>
      <description>&lt;P&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 17:01:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/655777#M111104</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2023-08-28T17:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Armis alerts logs parsing issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/655880#M111117</link>
      <description>&lt;P&gt;The packet field appears to encoded or encrypted.&amp;nbsp; You would have to get with the vendor to determine how to make the field legible , if it can be done at all.&amp;nbsp; It's possible this is data straight off the wire and that you would need the SSL certificate to process the data - not something one can do in SPL.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 16:41:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-Armis-alerts-logs-not-parsing-correctly/m-p/655880#M111117</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-08-28T16:41:01Z</dc:date>
    </item>
  </channel>
</rss>

