ArcSight CEF Cisco FireSight Syslog Parsing Issues

Idea ID 2778283

ArcSight CEF Cisco FireSight Syslog Parsing Issues

Hi Microfocus

We are having issues with parsing of CEF events by FireSight smart connector. Multiple CEF events are being bundled up into one CEF event hences causing loss in data and severe parsing issues related to host names and content in itself. Have this issue been raised or addressed before? If so can you help us with this?

 

We opened a support ticket and they directed us towards here.

7 Comments
Micro Focus Contributor
Micro Focus Contributor
Status changed to: Waiting for Votes

Please add the ticket number this was submitted to Support  under so this can be further evaluated.

Contributor.. Contributor..
Contributor..
Service Request ID:
SD02681425
Service request type:
Product Technical Issue
Product:
arcsight smart connectors
Knowledge Partner Knowledge Partner
Knowledge Partner

udp/tcp issue? can you switch to UDP?

Contributor.. Contributor..
Contributor..

The CEF agent is forwarding the data to Smart Connector on UDP port 514.

Knowledge Partner Knowledge Partner
Knowledge Partner

@dalesio  Openly speaking - this sounds like a config issue and has nothing to do with an FR. @shankar_gopal  @dalesio  it looks like support starts to send everybody to idea exchange nowadays, instead of fixing issues - this is a situation, nobody of us might want.

@COEST please take also care of this - I think we need to ensure idea exchange is for feature request and not a dumpster for bug/issues that should be handles in support tickets.

KR 

A

Knowledge Partner Knowledge Partner
Knowledge Partner

@shankar_gopal  where does the "mangeling of information" happen? 

did you enable aggregation somewhere? 

are the settings for the e-streamer software set correctly, are newline characters added.

what happens if you do a tcpdump, copy the  CEF messages out, and send them manually to the smart connector.  echo "msg" >> /dev/udp/localhost/514

Are you working on  a connector appliance?

KR

A

Community Manager Community Manager
Community Manager

@vitz1, thank you for all your help and the note sent. Did you see other similar instances of support issues submitted as ideas that you could share with me?

The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.