Hi people! I have a customer who has an event source that writtes it events into Application Channel of Windows Events. We don't have any problem to collect those events but, Netwitness try to parse them as Windows Events. I wonder if there is any way to take the value of one metadata (let's say "msg") and process it as a CEF message.
Any sugestions?
any sample events you can provide?