Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please help me this parser of Symantec logs #10454

Open
NellyThai opened this issue May 8, 2024 · 7 comments
Open

Please help me this parser of Symantec logs #10454

NellyThai opened this issue May 8, 2024 · 7 comments
Assignees
Labels
Parser Parser specialty review needed

Comments

@NellyThai
Copy link

Describe the bug
I tested the symantec logs in my own environment. My conclusion is that the data connector is likely broken. Especially the log format in the step 3 of the data connector is incorrect, leading to incorrect parsing of syslog in the first place. And the parser query is also likely broken.

Here is the proof. After using the following query in the ASC, you can actually get the logs that resembles the tailed logs. Needless to say, the computer and the hostname column are all incorrectly parsed, not to mention the actual SyslogMessage. This proves that the oms agent has been uploading the logs all this time, the problem is with the custom log format given in the data connector.

For reference, the original logs from port 514 looks like this.
1 2024-04-04 08:29:22 3 10.1.89.51 - - authentication_failed DENIED "Technology/Internet;AdobeCC" "-" 407 TCP_DENIED CONNECT "-" tcp cc-api-data.adobe.io 443 / - - "CRWindowsClient" 192.168.8.32 0 0 - "none" "none" 443 "Unavailable" unavailable

I got confirmation from the Symantec team, that is the log from Symantec.

@v-sudkharat v-sudkharat added the Parser Parser specialty review needed label May 9, 2024
@v-rusraut
Copy link
Contributor

Hi @NellyThai,
Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 16 May 2024. Thanks!

@v-rusraut
Copy link
Contributor

Hi @NellyThai,
Please help us to understand which Symantec solution you are using and also share error screen shots.
Thanks

@NellyThai
Copy link
Author

NellyThai commented May 15, 2024 via email

@NellyThai
Copy link
Author

NellyThai commented May 15, 2024 via email

@NellyThai
Copy link
Author

NellyThai commented May 17, 2024 via email

@v-rusraut
Copy link
Contributor

Hi @NellyThai,
Error screenshot not visible, please provide error screenshot to below email id:
v-rusraut@microsoft.com
Thanks

@NellyThai
Copy link
Author

NellyThai commented May 20, 2024 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Parser Parser specialty review needed
Projects
None yet
Development

No branches or pull requests

3 participants