New Ranks & Badges For The Community!
Notice something different? The ranks and associated badges have gone "Star Fleet". See what they all mean HERE
Highlighted
Cadet 3rd Class
Cadet 3rd Class
278 views

Trust-to-Untrust-Unknown-Apps

I am trying to trouble shoot high number of denied traffic events. In one of the fields from Raw logs I found the following

deviceCustomString1="Trust-to-Untrust-Unknown-Apps"

for all the denied traffic. My guess is this is the reason why the traffic is denied but I have failed to find any documentation reagarding this.

Is this custom made or have some predefined meaning in Arcsight?

Any help is appreciated

Labels (2)
0 Likes
1 Reply
Highlighted
Fleet Admiral
Fleet Admiral

Devicecustomstring is often used to map certain names or references to the logsource, the information itself is not something that is normally populated by ArcSight itself.

For example traffic logs from Cisco firewalls might include the rule number, policy name, outcome name etc, and same with web application firewalls which might have certain App rules, populating the name of the rule that was hit.

Each supported application normally have specific documentation either provided by the vendor from their site, or in our Connector Documentation section, which usually has a list of all fields that are mapped and the meaning behind their value

-----------------------------------------------------------------------------------------
All topics and replies made is based on my personal opinion, viewpoint and experience, it does not represent the viewpoints of MicroFocus.
All replies is based on best effort, and can not be taken as official support replies.
//Marius
0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.