String parsing examples & manuals
Good afternoon Folks
On a recent enVision training course it had been hoped that string parsing would be covered. Unfortunately it was not. Does anyone have examples of how this is done and implemented or even have a manual that would show each step of the process?
New envision user
Thanks for your reply.
String parsing is terms of:
message/event text is parsed and investigated for specific string (or word), if specific string is there an action is taken. i.e. an alert
I hope this answers your question.
It sounds like you just want to do a simple alert with a filter on one or more of the variables in the message.
High Level Overview of the Process:
Create a view
Add the desired devices
Add the desired events from those devices
Add filters to variables in those events
Apply any output actions desired
Finish the View
As far as the more in-depth details, refer to your enVision course materials
Also, if I understand your question properly, I think you want to select all event categories in your statement level and then in the filter use content REGEX xxx.
Thanks for your reply. You are quite right, all I want to do is read a message string and if I see "A!!" envision will do "X". However the course material does not cover what you have described. This level of skill was promised in the "advanced" course, which is, according to RSA training, "currently under development"
If you have anything you could email me, I would appreciate it.