
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi, I'm setting up our IIS 8.5 logs and we added the column X-forwader to get the original source/attacker instead of the web server IP. I can see this info in our Logger with column name "AD.x-Forwarded-For" but I cannot find this field in the ArcSight Express 4.0 console. Can you please guide in setting this event?
Thanks and regards,
Richel
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks! I will try this option during my maintenance and will let you know the outcome. So far adding this in the ESM sever.properties fix my issue.
"turbo.enabled=false"

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Richel. You can add a conditional mapping. Go to the ESM console and right click on the connector that is pulling logs from logger. Then Send Command -> Mapping -> Get additional Names. Take notes about the additional fields you want and map them through the same path on "Map additional names".

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks! I will try this option during my maintenance and will let you know the outcome. So far adding this in the ESM sever.properties fix my issue.
"turbo.enabled=false"


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content