Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Parser for Semperis DSP logs #2211

Closed
muditrao82 opened this issue Sep 29, 2023 · 6 comments · Fixed by #2259
Closed

Parser for Semperis DSP logs #2211

muditrao82 opened this issue Sep 29, 2023 · 6 comments · Fixed by #2259
Assignees

Comments

@muditrao82
Copy link

What is the sc4s version ?
sc4s version=2.49.8
Is there a pcap available?
attached in log files.

What the vendor name?
Semperis DSP

What's the product name?
Semperis DSP

** Feature Request description: **
Logs parser for Semperis DSP

** Should it support TCP or UDP?**
UDP

** Do you want to have it for local usage or prepare a github PR? **
demologs.txt

@ikheifets-splunk
Copy link
Contributor

Its seems that is already duplicating discussion on Splunk user group

@ikheifets-splunk ikheifets-splunk self-assigned this Oct 12, 2023
@ikheifets-splunk
Copy link
Contributor

ikheifets-splunk commented Oct 13, 2023

@muditrao82 are you solved this issue already in splunk user group? If yes, I think you can make pull request here, we are an open source project. If you don't published this question we can ask to share parser from "Splunk user group"

@muditrao82
Copy link
Author

@ikheifets-splunk this issue has not been resolved from Splunk user group. My main technical contact and SE at Splunk informed me that you were working on completing the parser for Semperis DSP logs. What is the current status and when will this be completed?

@ikheifets-splunk ikheifets-splunk linked a pull request Nov 6, 2023 that will close this issue
@ikheifets-splunk
Copy link
Contributor

ikheifets-splunk commented Nov 6, 2023

Hello, @muditrao82 !
I created a pull request for this issue.
If you wanna test it before release please pull development sc4s version

@muditrao82
Copy link
Author

muditrao82 commented Nov 13, 2023 via email

@ikheifets-splunk
Copy link
Contributor

ikheifets-splunk commented Nov 13, 2023

Hello, @muditrao82 !

Usually we not parsing such formats and only identifying vendor and product.
But after you mentioned that important for you, it I updated my PR and it's working like that:

Screenshot 2023-11-13 at 23 23 27

P.S. Hope that it would be okay for you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants