Getting Data In
Highlighted

How to set an Approriate Sourcetype for Qradar CSV Report when add Data into Splunk?

New Member

I have a CSV Report look like this:

<13>Jun 12 14:04:28 10.0.115.117 AgentDevice=WindowsLog AgentLogFile=Application PluginVersion=1.0.14 Source=MSSQLSERVER Computer=APP-SP1.hdbank.com.vn User=adminsharepoint Domain=HDBANK EventID=3221243928 EventIDCode=18456 EventType=16 EventCategory=4 RecordNumber=11666477 TimeGenerated=1528787067 TimeWritten=1528787067 Message=Login failed for user 'HDBANK\adminsharepoint'. Reason: Failed to open the explicitly specified database. [CLIENT: ] ,3c 31 33 3e 4a 75 6e 20 31 32 20 31 34 3a 30 34 3a 32 38 20 31 30 2e 30 2e 31 31 35 2e 31 31 37 20 41 67 65 6e 74 44 65 76 69 63 65 3d 57 69 6e 64 6f 77 73 4c 6f 67 09 41 67 65 6e 74 4c 6f 67 46 69 6c 65 3d 41 70 70 6c 69 63 61 74 69 6f 6e 09 50 6c 75 67 69 6e 56 65 72 73 69 6f 6e 3d 31 2e 30 2e 31 34 09 53 6f 75 72 63 65 3d 4d 53 53 51 4c 53 45 52 56 45 52 09 43 6f 6d 70 75 74 65 72 3d 41 50 50 2d 53 50 31 2e 68 64 62 61 6e 6b 2e 63 6f 6d 2e 76 6e 09 55 73 65 72 3d 61 64 6d 69 6e 73 68 61 72 65 70 6f 69 6e 74 09 44 6f 6d 61 69 6e 3d 48 44 42 41 4e 4b 09 45 76 65 6e 74 49 44 3d 33 32 32 31 32 34 33 39 32 38 09 45 76 65 6e 74 49 44 43 6f 64 65 3d 31 38 34 35 36 09 45 76 65 6e 74 54 79 70 65 3d 31 36 09 45 76 65 6e 74 43 61 74 65 67 6f 72 79 3d 34 09 52 65 63 6f 72 64 4e 75 6d 62 65 72 3d 31 31 36 36 36 34 37 37 09 54 69 6d 65 47 65 6e 65 72 61 74 65 64 3d 31 35 32 38 37 38 37 30 36 37 09 54 69 6d 65 57 72 69 74 74 65 6e 3d 31 35 32 38 37 38 37 30 36 37 09 4d 65 73 73 61 67 65 3d 4c 6f 67 69 6e 20 66 61 69 6c 65 64 20 66 6f 72 20 75 73 65 72 20 27 48 44 42 41 4e 4b 5c 61 64 6d 69 6e 73 68 61 72 65 70 6f 69 6e 74 27 2e 20 52 65 61 73 6f 6e 3a 20 46 61 69 6c 65 64 20 74 6f 20 6f 70 65 6e 20 74 68 65 20 65 78 70 6c 69 63 69 74 6c 79 20 73 70 65 63 69 66 69 65 64 20 64 61 74 61 62 61 73 65 2e 20 5b 43 4c 49 45 4e 54 3a 20 3c 6c 6f 63 61 6c 20 6d 61 63 68 69 6e 65 3e 5d 20 0d,PDEzPkp1biAxMiAxNDowNDoyOCAxMC4wLjExNS4xMTcgQWdlbnREZXZpY2U9V2luZG93c0xvZwlBZ2VudExvZ0ZpbGU9QXBwbGljYXRpb24JUGx1Z2luVmVyc2lvbj0xLjAuMTQJU291cmNlPU1TU1FMU0VSVkVSCUNvbXB1dGVyPUFQUC1TUDEuaGRiYW5rLmNvbS52bglVc2VyPWFkbWluc2hhcmVwb2ludAlEb21haW49SERCQU5LCUV2ZW50SUQ9MzIyMTI0MzkyOAlFdmVudElEQ29kZT0xODQ1NglFdmVudFR5cGU9MTYJRXZlbnRDYXRlZ29yeT00CVJlY29yZE51bWJlcj0xMTY2NjQ3NwlUaW1lR2VuZXJhdGVkPTE1Mjg3ODcwNjcJVGltZVdyaXR0ZW49MTUyODc4NzA2NwlNZXNzYWdlPUxvZ2luIGZhaWxlZCBmb3IgdXNlciAnSERCQU5LXGFkbWluc2hhcmVwb2ludCcuIFJlYXNvbjogRmFpbGVkIHRvIG9wZW4gdGhlIGV4cGxpY2l0bHkgc3BlY2lmaWVkIGRhdGFiYXNlLiBbQ0xJRU5UOiA8bG9jYWwgbWFjaGluZT5dIA0=

How do i set an Approriate Sourcetype for this kind of Report or How to configure it?

0 Karma