MaryCordova

Frequent Contributor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-08-04
22:49
Re: P-McAfee_ePO_1.0.0.2.arb
Woot! Successful install of package
Thanks Prentice!
MaryCordova

Frequent Contributor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-10-01
18:55
Re: P-McAfee_ePO_1.0.0.2.arb
Is there supposed to be a parser override for this?
MaryCordova

Frequent Contributor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-12-03
23:08
Re: P-McAfee_ePO_1.0.0.2.arb
prentice@hpe.co

Honored Contributor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-12-21
17:58
Re: P-McAfee_ePO_1.0.0.2.arb
MaryCordova

Frequent Contributor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2016-02-03
00:29
Re: P-McAfee_ePO_1.0.0.2.arb
So I believe there is definitely supposed to be a parser override. Below is a screenshot from the wiki documentation:
Also, parsed events don't contain a target or attacker hostname but the raw events have that information in their schema as agenthostname. Raw events also have the username which is not available in parsed events as well as some other pieces of data.
deathbywedgie1

Frequent Contributor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2016-02-04
00:57
Re: P-McAfee_ePO_1.0.0.2.arb
Sorry, that one isn't ringing a bell at the moment.
MaryCordova

Frequent Contributor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2016-02-04
22:58
Re: P-McAfee_ePO_1.0.0.2.arb
/ deathbywedgie / chrisb / awmorris
OMG...the parser is attached to the WIKI...THAT IS A LINK!!!
<sorry lol>
- « Previous
-
- 1
- 2
- Next »