

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
CEF Folder Follower
Hi,
Can anyone help me out on how to create a CEF Folder Follower Connector ?
Thanks,
Sahaya

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi,
I wish you posted your cef properties file.
Bummer that the arcsight flex-connector install doesn't include any sample properties files (as far as I can tell) for the cef log.
I am using "ArcSight FlexConnector Multiple Folder File" connector with a type of "cef" (option 3).
Thanks
Kit Lueder


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
cef_files is SmartConnector out-of-box parser.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I don't understand how to do the mapping. Is there a properties file for the mapping? I.e. it is not just a straight cef-to-cef pass-through with no mapping?
Thanks
To elaborate:
I can do a regex parsing, and it will parse the seven header fields of the CEF record, but then the remainer key=value fields are not parsed.
Or I can do a cef parsing, in which case the CEF header fields are not parsed and end up being a bunch of vertical bars on the output-side.
Since CEF is a basic arcsight format, I would think that they have basic support for it?
Thanks
- « Previous
-
- 1
- 2
- Next »