<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Parsing Forcepoint CASB CEF logs in Splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521042#M88053</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp;Yes, the sourcetype in props.conf matches what is set in inputs.conf for this custom Forcepoint CASB app.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Sep 2020 12:20:46 GMT</pubDate>
    <dc:creator>geoffmoraes</dc:creator>
    <dc:date>2020-09-23T12:20:46Z</dc:date>
    <item>
      <title>Parsing Forcepoint CASB CEF logs in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/520254#M87950</link>
      <description>&lt;P&gt;I need some help with parsing Forcepoint CASB CEF logs in Splunk. The data does not seem to parse the epoch time stamps and all comes in as one event. I need to break these up into individual events and also parse the epoch time stamp in the format&amp;nbsp; "&lt;STRONG&gt;%Y-%m-%d %H:%M:%S&lt;/STRONG&gt;"&amp;nbsp;on ingestion into splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SAMPLE DATA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;CEF:0|Forcepoint CASB|Cloud Service Monitoring|1.0|63575192763|Activity|0|act=Monitor app= cat=Normal Activity cs1= destinationServiceName=Office365 deviceExternalId= deviceFacility=true deviceProcessName=loadBalancers dhost= dpriv=User dst=0.0.0.0 duser=14dd43c6-a792-4c07-a33b-c5e561a129de dvc=10.1.2.12 dvchost=somedomain end=1600408516000 externalId=0 fsize=-1 msg=//United States/Unknown outcome=Success proto= reason=modify request= requestClientApplication=Unknown/Unknown/"" rt=1600408516000 sourceServiceName=Unmanaged src=someIP start=1600408516000 suser=  cs2= cs3= cs5=false cs6= dproc=Unknown flexString1=mc_rg-int-qa-eus02_aks-int01-qa-eus02_eastus2,kubernetes-internal cs4=14dd43c6-a792-4c07-a33b-c5e561a129de flexString2= AD.ThreatRadarCategory= AD.TORNetworks= AD.MaliciousIPs= AD.AnonymousProxies= AD.IPChain=someIP AD.IPOrigin=External AD.samAccountName=14dd43c6-a792-4c07-a33b-c5e561a129de
CEF:0|Forcepoint CASB|Cloud Service Monitoring|1.0|63575216734|Activity|0|act=Monitor app= cat=Normal Activity cs1= destinationServiceName=Office365 deviceExternalId= deviceFacility=false deviceProcessName= dhost= dpriv=User dst=0.0.0.0 duser=someuser_849fcb2777e9@somedomain.onmicrosoft.com dvc=10.1.2.12 dvchost=somedomain end=1600406172000 externalId=0 fsize=-1 msg=//United States/Unknown outcome=Success proto= reason=login request= requestClientApplication=Unknown/Unknown/"" rt=1600406172000 sourceServiceName=Unmanaged src=someIP start=1600406172000 suser=  cs2= cs3= cs5=false cs6= dproc=Unknown flexString1= cs4=someaccount9@somedomain.onmicrosoft.com flexString2= AD.ThreatRadarCategory= AD.TORNetworks= AD.MaliciousIPs= AD.AnonymousProxies= AD.IPChain=someIP AD.IPOrigin=Internal AD.samAccountName=someaccount9@somedomain.onmicrosoft.com
CEF:0|Forcepoint CASB|Cloud Service Monitoring|1.0|63575216736|Activity|0|act=Monitor app= cat=Normal Activity cs1= destinationServiceName=Office365 deviceExternalId= deviceFacility=true deviceProcessName= dhost= dpriv=User dst=0.0.0.0 duser=someaccount@somedomain.onmicrosoft.com dvc=10.1.2.12 dvchost=somedomain end=1600405713000 externalId=0 fsize=-1 msg=//United States/Unknown outcome=Success proto= reason=login request= requestClientApplication=Unknown/Unknown/"" rt=1600405713000 sourceServiceName=Unmanaged src=someIP start=1600405713000 suser=  cs2= cs3= cs5=false cs6= dproc=Unknown flexString1= cs4=someaccount@somedomain.onmicrosoft.com flexString2= AD.ThreatRadarCategory= AD.TORNetworks= AD.MaliciousIPs= AD.AnonymousProxies= AD.IPChain=someIP AD.IPOrigin=External AD.samAccountName=someaccount@somedomain.onmicrosoft.com
CEF:0|Forcepoint CASB|Cloud Service Monitoring|1.0|63575216738|Activity|0|act=Monitor app= cat=Normal Activity cs1= destinationServiceName=Office365 deviceExternalId= deviceFacility=false deviceProcessName= dhost= dpriv=User dst=0.0.0.0 duser=someaccount@somedomain.com dvc=10.1.2.12 dvchost=somedomain end=1600405674000 externalId=0 fsize=-1 msg=/1225/United States/Unknown outcome=Success proto= reason=login request= requestClientApplication=Unknown/Unknown/"" rt=1600405674000 sourceServiceName=Unmanaged src=someIP start=1600405674000 suser= cs2= cs3= cs5=false cs6= dproc=Unknown flexString1= cs4=someaccount flexString2= AD.ThreatRadarCategory= AD.TORNetworks= AD.MaliciousIPs= AD.AnonymousProxies= AD.IPChain=someIP AD.IPOrigin=Internal AD.samAccountName=someaccount
CEF:0|Forcepoint CASB|Cloud Service Monitoring|1.0|63575216735|Activity|0|act=Monitor app= cat=Normal Activity cs1= destinationServiceName=Office365 deviceExternalId= deviceFacility=false deviceProcessName= dhost= dpriv=User dst=0.0.0.0 duser=someaccount9@somedomain.onmicrosoft.com dvc=10.1.2.12 dvchost=somedomain end=1600406165000 externalId=0 fsize=-1 msg=//United States/Unknown outcome=Success proto= reason=login request= requestClientApplication=Unknown/Unknown/"" rt=1600406165000 sourceServiceName=Unmanaged src=someIP start=1600406165000 suser=  cs2= cs3= cs5=false cs6= dproc=Unknown flexString1= cs4=someaccount@somedomain.onmicrosoft.com flexString2= AD.ThreatRadarCategory= AD.TORNetworks= AD.MaliciousIPs= AD.AnonymousProxies= AD.IPChain=someIP AD.IPOrigin=Internal AD.samAccountName=someaccount@somedomain.onmicrosoft.com&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assume that the sourcetype is called "cefevents" for this example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;PROPS.CONF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[cefevents]
LINE_BREAKER = CEF:0.+[\r\n]?
MAX_TIMESTAMP_LOOKAHEAD = 600
NO_BINARY_CHECK = true
KV_MODE = none
SHOULD_LINEMERGE = false
TIME_FORMAT = %s%Q
TIME_PREFIX = \s(start|end|rt)\=&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The regex looks ok on regex101&amp;nbsp;&lt;A href="https://regex101.com/r/hf7ZJs/1" target="_self"&gt;https://regex101.com/r/hf7ZJs/1&lt;/A&gt;&amp;nbsp;but doesn't work on this data.&lt;/P&gt;&lt;P&gt;I have also attempted using the props.conf from&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/487/" target="_self"&gt;https://splunkbase.splunk.com/app/487/&lt;/A&gt;&amp;nbsp;but that does not help either.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 07:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/520254#M87950</guid>
      <dc:creator>geoffmoraes</dc:creator>
      <dc:date>2020-09-18T07:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Forcepoint CASB CEF logs in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/520313#M87952</link>
      <description>&lt;P&gt;TIME_PREFIX - you can't set multiple prefixes. set any of them. I have used end=( you can change it)&lt;/P&gt;&lt;P&gt;TIME_FORMAT - you can format the way you want at the time of search. we can't enforce to show time format for each source type. TIME_FORMAT will tell splunk in which format time is there in event. so that Spunk understands time correctly.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ __auto__learned__ ]
SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
TIME_PREFIX=end\=&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 18 Sep 2020 12:25:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/520313#M87952</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-18T12:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Forcepoint CASB CEF logs in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521037#M88051</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;If I take a sample cef file and upload it to splunk, these values work as expected.&lt;/P&gt;&lt;P&gt;However, if I create a custom deployment app on a Heavy Forwarder with these values in props.conf, it has no effect on the incoming logs. The logs have no line breaks and the time stamp is that of the log file drop on the server with the UF.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 12:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521037#M88051</guid>
      <dc:creator>geoffmoraes</dc:creator>
      <dc:date>2020-09-23T12:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Forcepoint CASB CEF logs in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521040#M88052</link>
      <description>&lt;P&gt;Did you set sourcetype? you should should use sourcetype that you have mentioned in inputs.conf in heavy forwarder props.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 12:12:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521040#M88052</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-09-23T12:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Forcepoint CASB CEF logs in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521042#M88053</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/129407"&gt;@thambisetty&lt;/a&gt;&amp;nbsp;Yes, the sourcetype in props.conf matches what is set in inputs.conf for this custom Forcepoint CASB app.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 12:20:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521042#M88053</guid>
      <dc:creator>geoffmoraes</dc:creator>
      <dc:date>2020-09-23T12:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Parsing Forcepoint CASB CEF logs in Splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521229#M88077</link>
      <description>&lt;P&gt;This has been resolved.&lt;/P&gt;&lt;P&gt;I had the props.conf under&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNKHOME\etc\deployment-apps\&amp;lt;app_name&amp;gt;\local\&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I removed that file and instead added its contents to the existing props.conf under&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; $SPLUNKHOME\etc\apps\search\local\&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and the line-breaking and time-stamp parsing work as expected.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 08:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Parsing-Forcepoint-CASB-CEF-logs-in-Splunk/m-p/521229#M88077</guid>
      <dc:creator>geoffmoraes</dc:creator>
      <dc:date>2020-09-24T08:43:29Z</dc:date>
    </item>
  </channel>
</rss>

