<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The precise sourcetype setting when importing ESET logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429367#M94181</link>
    <description>&lt;P&gt;hi @dum0785,&lt;/P&gt;

&lt;P&gt;Did @inventsekar answer your question? If not, could you  give us some more details about your problem? In general, you have a better chance of getting your question answered the more context you provide. Thanks and happy Splunking!&lt;/P&gt;</description>
    <pubDate>Wed, 29 Aug 2018 21:49:30 GMT</pubDate>
    <dc:creator>mstjohn_splunk</dc:creator>
    <dc:date>2018-08-29T21:49:30Z</dc:date>
    <item>
      <title>The precise sourcetype setting when importing ESET logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429363#M94177</link>
      <description>&lt;P&gt;I currently use the ESET Remote Administrator.&lt;BR /&gt;
However, I can not divide log fields with sourcetype.&lt;BR /&gt;
Please tell me the precise sourcetype setting when importing ESET logs.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2018-08-28T10:59:14+09:00   eset.user.info  {"message":"1 2018-08-28T01:59:14.307Z iptpeset01 ERAServer 5360 - -   {\"event_type\":\"Audit_Event\",\"ipv4\":\"172.18.1.30\",\"hostname\":\"eset01\",\"source_uuid\":\"014b605e-aede-40a3-b15e-c2bc1b3509a5\",\"occured\":\"28-Aug-2018 01:59:14\",\"severity\":\"Information\",\"domain\":\"Native user\",\"action\":\"Logout\",\"target\":\"Administrator\",\"detail\":\"Logging out native user 'Administrator'.\",\"user\":\"00000000-0000-0000-7002-000000000002\",\"result\":\"Success\"}"}
2018-08-28T11:34:16+09:00   eset.user.warn  {"message":"1 2018-08-28T02:34:16.220Z iptpeset01 ERAServer 5360 - -   {\"event_type\":\"Threat_Event\",\"ipv4\":\"172.17.18.249\",\"hostname\":\"local\",\"source_uuid\":\"e2b5397c-c61b-43e0-9ae6-f53acf0cae7b\",\"occured\":\"28-Aug-2018 02:33:47\",\"severity\":\"Warning\",\"threat_type\":\"test file\",\"threat_name\":\"Eicar\",\"scanner_id\":\"HTTP filter\",\"scan_id\":\"virlog.dat\",\"engine_version\":\"17954 (20180827)\",\"object_type\":\"file\",\"object_uri\":\"http://www.eicar.org/download/eicar.com.txt\",\"action_taken\":\"connection terminated\",\"threat_handled\":true,\"need_restart\":false,\"username\":\"yamada\",\"processname\":\"C:\\\\Program Files\\\\Mozilla Firefox\\\\firefox.exe\",\"circumstances\":\"Threat was detected upon access to web.\",\"hash\":\"3395856CE81F2B7382DEE72602F798B642F14140\"}"}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 29 Aug 2018 07:05:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429363#M94177</guid>
      <dc:creator>dum0785</dc:creator>
      <dc:date>2018-08-29T07:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: The precise sourcetype setting when importing ESET logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429364#M94178</link>
      <description>&lt;P&gt;maybe, ESET app can give you some ideas...&lt;BR /&gt;
TA for Eset Remote Administrator&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3867/#/overview"&gt;https://splunkbase.splunk.com/app/3867/#/overview&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;basically, sourcetype you can set it your self whatever convenient to you.. &lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 07:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429364#M94178</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-08-29T07:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: The precise sourcetype setting when importing ESET logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429365#M94179</link>
      <description>&lt;P&gt;Is it impossible with Edit Source's Advanced? &lt;BR /&gt;
Or regular expression..&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 07:28:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429365#M94179</guid>
      <dc:creator>dum0785</dc:creator>
      <dc:date>2018-08-29T07:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: The precise sourcetype setting when importing ESET logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429366#M94180</link>
      <description>&lt;P&gt;i am actually not getting your question.. &lt;BR /&gt;
when we ingest/on board log files, on the inputs.conf file, we can assign any source/sourcetype as per our convenience.. the standard log files like linux/windows may have some standards as they are common.&lt;/P&gt;

&lt;P&gt;for log files like ESET app, if i am in your place, i would simply assign "eset" as the sourcetype and the file's fullpath would be the source.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 07:54:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429366#M94180</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2018-08-29T07:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: The precise sourcetype setting when importing ESET logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429367#M94181</link>
      <description>&lt;P&gt;hi @dum0785,&lt;/P&gt;

&lt;P&gt;Did @inventsekar answer your question? If not, could you  give us some more details about your problem? In general, you have a better chance of getting your question answered the more context you provide. Thanks and happy Splunking!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Aug 2018 21:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/The-precise-sourcetype-setting-when-importing-ESET-logs/m-p/429367#M94181</guid>
      <dc:creator>mstjohn_splunk</dc:creator>
      <dc:date>2018-08-29T21:49:30Z</dc:date>
    </item>
  </channel>
</rss>

