All Apps and Add-ons

How to parse Trend Micro Deep Security Log Inspection in XML?

alaquerre
Explorer

Hi everyone,

So in the past our customer was using a combination of Splunk and Ossec agents and that worked splendidly (to it's limit anyway) and now they have installed Deep Security package in order to use the OSSEC feature and collect Windows logs instead of the Splunk agent so as to avoid having multiple agents installed across the infrastructure. The Solution was to forward all of the logs towards a single Splunk Agent that will then collect and send to the Splunk Server. Now the logs are all coming in beautifully except for the format of the windows logs that are no longer being sent in XML format (as was the case with the Splunk Agent) which is now a bit of an issue for all of our dashboards that relied on that type of Parsing. Does anyone have any suggestions on how i could parse those logs coming from the Log Inspection in the same was as the Splunk Forwarder would ?

Thanks 😃

Alexandre,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...