New Ranks & Badges For The Community!
Notice something different? The ranks and associated badges have gone "Star Fleet". See what they all mean HERE
Highlighted
Captain
Captain
542 views

SourceFire Payload

Is there anyone here experiencing not able to copy/paste payload of IDS events from SourceFire?  Is this a connector or console issue?  We are using the latest version of ESM and ArcMC.

Thanks!

Labels (3)
Tags (2)
0 Likes
4 Replies
Highlighted
Captain Captain
Captain

What connector version are you using for this?

0 Likes
Highlighted

This is an encoding issue when you try to copy and paste from the hex stream emulator.

If you copy from the ASCII output it will encode to a UTF application without problems.

If you have access to SourceFire's Management Center then you can copy the hex offset stream from there.

You can also click the icon "Launch external payload viewer" in the payload section where Wireshark or another pcap tool can encode the hex streams into a UTF format.

The check box for "Convert Text to Pcap" should be marked for this to work.

And if you haven't set an external payload viewer in your ArcSight console that can be done under Edit > Preferences > Programs > Preferred Payload Viewer.

To copy from Wireshark you can right click the packet and select Follow TCP stream and encode that window with "Hex Dump".

To copy a specific hex string within Wireshark select the desired string from the viewer and then right click the packet to: Copy > Bytes > Offset Hex.  This will allow you to paste a UTF readable hex value.

This has been a common question for me in the field so I hope this helps your situation.

Cheers!

-Chris

0 Likes
Highlighted
Knowledge Partner Knowledge Partner
Knowledge Partner

When i want to copy payload from SourceFire, I take the event, add it to new case, get into the event, copy the pacload (ctrl-c)

and paste somewhere into any field of the ArcSight case,

From there i can copy and paste it everywhere...

Hope that helps

Cheers

Andreas

0 Likes
Highlighted
Captain
Captain

This is very helpful Chris!  I really appreciate your feedback on this.

Salute!

Richel

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.