- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
SA Log Parser Creation
Hi Folks,
Is anyone can help me out how the xml log parsing works in SA? I would like to learn and understand how xml works in SA - creation,modification of parsers. I have checked in sadocs but couldnt help me.
It could be appreciable if any one sent me any links regarding xml log parsing.
Regards
Pranav Sankar
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I just created a new video on using the new ESI tool. Check it out
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Visit here for parser regarding info.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Can anyone explain how we will write XML parsers?
For example when i worked for Arcsight Flex Parser first ill go with analyzing events,Regex Creation,Tokens,Patterns Concepts and finally deployment likewise how we will write XML parser here?
when i checked in above docs i couldnt find xml parsing concept.My queries are:
1.After analyzing raw events how we will make them to Header and message part in XML
2.Mapping concepts.
Hope this could clear and im eagerly waiting for your valuable comments.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Pranav if you post a few sample log messages here (make sure any sensitive data is anonymised) I'll do an example here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Dave its not possible with my customer view point we are not supposed to share any single point of logs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Oh dear. Then the best course of action is to sign up for the course that I outlined in Custom Parsers .
There are also some online learning course on the Event Source Integration Tool.
The course code is:
RSA-ENVESI
This is a free e-learning course you just need to register.
https://edu.corp.emc.com/search/widgets_template1.aspx
If you have any problems accessing to content then Education Service can assist. You can contact them at
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
thats pretty cool stuff david ..First ill go through this courses.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
If you are interested I have a video that I did on walking through a sample log file and I could email you the link for it if you would like
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Dave,
Can you share the video link with me.
