All Apps and Add-ons

How to parse Trend Micro Deep Security Log Inspection in XML?

alaquerre
Explorer

Hi everyone,

So in the past our customer was using a combination of Splunk and Ossec agents and that worked splendidly (to it's limit anyway) and now they have installed Deep Security package in order to use the OSSEC feature and collect Windows logs instead of the Splunk agent so as to avoid having multiple agents installed across the infrastructure. The Solution was to forward all of the logs towards a single Splunk Agent that will then collect and send to the Splunk Server. Now the logs are all coming in beautifully except for the format of the windows logs that are no longer being sent in XML format (as was the case with the Splunk Agent) which is now a bit of an issue for all of our dashboards that relied on that type of Parsing. Does anyone have any suggestions on how i could parse those logs coming from the Log Inspection in the same was as the Splunk Forwarder would ?

Thanks 😃

Alexandre,

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...