000034098 - How to add the information included by a Data Enrichment Source to Syslog notifcation in RSA Security Analytics

Document created by RSA Customer Support Employee on Sep 28, 2016Last modified by RSA Customer Support on May 6, 2019
Version 4Show Document
  • View in full screen mode

Article Content

Article Number000034098
Applies ToRSA Product Set: Security Analytics, RSA NetWitness Logs & Network
RSA Product/Service Type: SA Event Stream Analysis
RSA Version/Condition: 10.5.x,10.6.x
Platform: CentOS
O/S Version: 6
IssueEnrichment Sources can be added to an ESA rule by following the SA user guide.
However, the additional information does not get added to the Syslog notification.
TasksModify Syslog template to include the additional data from the Enrichment Sources.
ResolutionIn order to add the information included by an Enrichment Source, please follow the steps below:
  1. Open the ESA rule and make a note of the Enrichment Source name under Enrichment Source column.
    e.g. TestEnrichment from the following screenshot.
    User-added image
  2. Open the template used for the ESA rule from Administration-System-Global Notifications-Templates.
  3. Add the following line at the top of the file.
    <#include "macros.ftl">
  4. Add the following line to the desired location within the template.
    xxx=<@event_meta_last "yyy"/> <#t>
    where xxx is any string value to indicate the start of the added information and yyy is the Enrichment Source name noted from step 1.
  5. Save the template and monitor the syslog messages.
  6. If the syslog messages still do not include the new information, modify the ESA rule to use another template, save, select the correct template, save and deploy the rule to ensure the deployed rule uses the right template.

With a csv file containing the following information-
address string,criticality integer,department string,1,SALES

and Criticality=<@event_meta_last "TestEnrichment"/> <#t> added to the syslog template, the following line will be added to the syslog message.
... Criticality=address=;criticality=1;department=SALES ...