• CEF event with syslog header gets device addres/hostname parsed wrong if CEF has dvc=entry

    Hello, we have CheckPoint firewalls sending events over syslog in CEF format. Problem is, that events has also the SYSLOG header containing deviceAddress. For ChceckPoints Identity Awareness events gets generated like this: Jan 13 14:25:36 xx.xx.xx…
  • The problem in viewing for IPAddress fields after running mysql query on ESM RedHat !

    Hi everybody I have access via SSH connection to the ArcSight ESM RedHat host. I want to create a customized dashboard panel with Grafana Dashboard Manager with the Mysql plugin. I configured the "my.cnf" file and granted it to the MySQL ArcSight database…
  • Flexconnector IPAddress or Hostname

    I have a trouble with a flexconnector, I created the regex and this works ok, but into the regular expression, I have one option that choose between IPaddress or hostname, for example two events: Regex: (\\d{8})\\s*(\\w{3})\\s*(?:(\\d \\.\\d \\.\\d \…