All Apps and Add-ons

How to parse Trend Micro Deep Security Log Inspection in XML?

alaquerre
Explorer

Hi everyone,

So in the past our customer was using a combination of Splunk and Ossec agents and that worked splendidly (to it's limit anyway) and now they have installed Deep Security package in order to use the OSSEC feature and collect Windows logs instead of the Splunk agent so as to avoid having multiple agents installed across the infrastructure. The Solution was to forward all of the logs towards a single Splunk Agent that will then collect and send to the Splunk Server. Now the logs are all coming in beautifully except for the format of the windows logs that are no longer being sent in XML format (as was the case with the Splunk Agent) which is now a bit of an issue for all of our dashboards that relied on that type of Parsing. Does anyone have any suggestions on how i could parse those logs coming from the Log Inspection in the same was as the Splunk Forwarder would ?

Thanks 😃

Alexandre,

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...