iSeries syslog with PowerTech Interact
We have an iSeries that is running PowerTech's Interact syslog utility to provide logs. We've pointed the output at enVision, but it's not parsing at this point. The iSeries shows up as "unknown", so we know the data is arriving. We have just installed enVision, so are still getting our feet wet.
We have another iSeries that we set up with FileReader and that data is coming in just fine.
I can see that the PowerTech syslog output has a couple of extra fields (that appear to define the version of Interact in use), and is using some PIPE delimiters and spaces instead of commas, etc... Has anyone created a customization for Interact?
I've not heard of that tool or seen a UDS for it, but it sounds useful. It should be an easy matter to create a UDS integration for it using the Event Source Integrator (ESI) tool. The company could also develop their own ESI package using the RSA Partner program.
Thanks for the reply Clarke, we are new to enVision and will have our professional services contact help us look at a UDS. I've also submitted a request to add support for Interact. Their site shows support for many other SIEM platforms.
I did speak with PowerTech following your device request and discussed our ESI Partner Program and there was some interest but the demand on their side hadn't reached critical mass. I received another request last week from a customer that I had sent over to PowerTech to help drive momentum. If you could also ping PowerTech we have partner resources available to engage.