Absent Member.
Absent Member.
1047 views

Map device receipt time -> End time

Hello,

Is it possible to map the device receipt time to the field end time without using a rule?

Regards,

Pedro Chaves

Labels (2)
0 Likes
10 Replies
Fleet Admiral
Fleet Admiral

Hi Pedro,

You may use map files on the connector but if you do that you will not be able to detect Time Issue.

Why you want to do this mapping?

If you have a huge difference it is maybe an useful information to take into consideration.

Now if it is short time, you may use Time Correction feature in Connector configuration.

I hope this information will be helpful.

Thanks

Kind Regards

Michael

0 Likes
Absent Member.
Absent Member.

Hi Michael,

Thank you for the reply.

We install a non supported connector and there is a issue on mapping the timestamps.

This is a temporary fix until the supported version is released.

Do you know how do I use the properties map to do this?

Thank you in advance.

Kind Regards,

Michael

0 Likes
Fleet Admiral
Fleet Admiral

Hi Pedro,

You have to modify the map.0.properties file placed in /ARCSIGHT_HOME$/Curent/user/agent/map directory

with the correct.

Maybe this will work in replacing <device vendor of the connector> by the correct value without <>.


event.deviceVendor,set.event.endTime

<device vendor of the connector>,deviceReceiptTime

Do not forget to restart the connector and check in agent.out.wrapper.log for this ERROR

If it is not working, You need to use set.expr, I can try to provide you a proper answer tomorrow.

If it is urgent, you may check in the Flex Dev Guide PDF, there are some pages about that.

Thanks

Kind Regards

Michael

0 Likes
Fleet Admiral Fleet Admiral
Fleet Admiral

Try:

map.0.properties:

set.expr(deviceReceiptTime).event.endTime

deviceReceiptTime

0 Likes
Absent Member.
Absent Member.

Hi,

Thanks for the reply.

I've tried those configurations and it doesn't seem to be working.

Regards,

Pedro Chaves

0 Likes
Fleet Admiral
Fleet Admiral

Which one of the two fields is currently set with the correct value? End Time or Device Receipt Time?

0 Likes
Absent Member.
Absent Member.

Hello,

Device Receipt Time.

0 Likes
Fleet Admiral
Fleet Admiral

Hi Pedro,

Could you please try in map.0.properties

event.deviceVendor,set.expr(deviceReceiptTime).event.endTime

<correctdevicevendor>,deviceReceiptTime

You have to restart the connector to permit this to work or to use the console to reload map files.

Thanks

Kind Regards

Michael

0 Likes
Absent Member.
Absent Member.

Hello Michael,

It doesn't work.

map.0.properties:

Events:

Regards,

Pedro Chaves

0 Likes
Fleet Admiral
Fleet Admiral

Hi Pedro,

You have asked for deviceReceiptTime!

With agentReceiptTime it is not possible because the agentTime arrive after the parsing of events.

Could you please show endTime and deviceReceiptTime to see if there are not equal?

Thanks

Kind Regards

Michael

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.