All Apps and Add-ons

How to parse Trend Micro Deep Security Log Inspection in XML?

alaquerre
Explorer

Hi everyone,

So in the past our customer was using a combination of Splunk and Ossec agents and that worked splendidly (to it's limit anyway) and now they have installed Deep Security package in order to use the OSSEC feature and collect Windows logs instead of the Splunk agent so as to avoid having multiple agents installed across the infrastructure. The Solution was to forward all of the logs towards a single Splunk Agent that will then collect and send to the Splunk Server. Now the logs are all coming in beautifully except for the format of the windows logs that are no longer being sent in XML format (as was the case with the Splunk Agent) which is now a bit of an issue for all of our dashboards that relied on that type of Parsing. Does anyone have any suggestions on how i could parse those logs coming from the Log Inspection in the same was as the Splunk Forwarder would ?

Thanks 😃

Alexandre,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...