<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trend Micro officescan and deepsecurity sourcetype as not papulating in Malware datamodel in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452453#M6310</link>
    <description>&lt;P&gt;Answering to myself:&lt;/P&gt;

&lt;P&gt;the naming convention for splunk apps to be appear in Splunk ES.&lt;/P&gt;

&lt;P&gt;Referrence URL: &lt;A href="https://docs.splunk.com/Documentation/ES/4.1.0/Install/InstallTechnologyAdd-ons#Import_add-ons_with_a_different_naming_convention"&gt;https://docs.splunk.com/Documentation/ES/4.1.0/Install/InstallTechnologyAdd-ons#Import_add-ons_with_a_different_naming_convention&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Jun 2019 14:09:06 GMT</pubDate>
    <dc:creator>rashid47010</dc:creator>
    <dc:date>2019-06-30T14:09:06Z</dc:date>
    <item>
      <title>Trend Micro officescan and deepsecurity sourcetype as not papulating in Malware datamodel</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452451#M6308</link>
      <description>&lt;P&gt;Maily I have three sourcetypes &lt;BR /&gt;
sourcetype=Officescan ( workstation logs( signature update, malware etc)&lt;BR /&gt;
sourcetype = deepsecurity ( servers, malware logs)&lt;BR /&gt;
sourcetype = trendmicro ( TrendMicro Control centre logs)&lt;/P&gt;

&lt;P&gt;I can see the sourecetype=trendmicro with tag=malware. but other I can't see although they have also tag=malware.&lt;/P&gt;

&lt;P&gt;secondly how can I made the app CIM compliant.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 08:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452451#M6308</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2019-06-30T08:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Trend Micro officescan and deepsecurity sourcetype as not papulating in Malware datamodel</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452452#M6309</link>
      <description>&lt;P&gt;In continuation of above, I install the TA_officescan TA on search head and on ES.&lt;BR /&gt;
on search Head I can see the proper field extration and tags assosication. whereas In ES i cant see field extration NOR tag association. &lt;BR /&gt;
am i missing something.?&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 12:53:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452452#M6309</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2019-06-30T12:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Trend Micro officescan and deepsecurity sourcetype as not papulating in Malware datamodel</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452453#M6310</link>
      <description>&lt;P&gt;Answering to myself:&lt;/P&gt;

&lt;P&gt;the naming convention for splunk apps to be appear in Splunk ES.&lt;/P&gt;

&lt;P&gt;Referrence URL: &lt;A href="https://docs.splunk.com/Documentation/ES/4.1.0/Install/InstallTechnologyAdd-ons#Import_add-ons_with_a_different_naming_convention"&gt;https://docs.splunk.com/Documentation/ES/4.1.0/Install/InstallTechnologyAdd-ons#Import_add-ons_with_a_different_naming_convention&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 14:09:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452453#M6310</guid>
      <dc:creator>rashid47010</dc:creator>
      <dc:date>2019-06-30T14:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Trend Micro officescan and deepsecurity sourcetype as not papulating in Malware datamodel</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452454#M6311</link>
      <description>&lt;P&gt;HI Rashid, which TA did you use for officescan?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 12:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Trend-Micro-officescan-and-deepsecurity-sourcetype-as-not/m-p/452454#M6311</guid>
      <dc:creator>amankhan1</dc:creator>
      <dc:date>2020-03-07T12:08:53Z</dc:date>
    </item>
  </channel>
</rss>

