SA incorrectly parsing RHEL, Solaris, Linux syslogs
Looking for some input on how to make these sources come up as their proper source.
Basically we're pushing the events via syslog to SA from RHEL, Solaris, and Linux environments (mixed environment, also have Windows). In SA, the events get shuffled into a few device types; crossbeam, rhlinux (includes tons of UFW logs, which would like to come up elsewhere as well), Solaris, and winevent_nic. The only reason I can find for these Unix boxes coming up in winevent_nic is the fact that they're negotiating/querying LDAP/AD.
How can we get these appearing as the appropriate device types?
Thanks in advance.
- Community Thread
- Forum Thread
- RSA NetWitness
- RSA NetWitness Platform
In enVision there was a way to tweak the priorities on a "multi" device to force enVision to consider events to first be RHEL, then AIX, then other stuff. We had to do this for a number of AIX boxes that one day decided to start logging as Linux instead.
Does SA have a similar capability?
Very interested in your outcome as we are considering a move to SA from enVision, and have tons of multi-devices.
SA doesn't have a capability to select device type manually, so we must invent a bicycle here.
For example you can disable parsers you don't use, or disable parsers that mix the device types for you for a limited time for device get a right type and then enable those parsers back.