AnsweredAssumed Answered

Parsing CEF within Windows Events

Question asked by Maximiliano Cittadini on Aug 14, 2018
Latest reply on Aug 15, 2018 by Eric Partington

Hi people! I have a customer who has an event source that writtes it events into Application Channel of Windows Events. We don't have any problem to collect those events but, Netwitness try to parse them as Windows Events. I wonder if there is any way to take the value of one metadata (let's say "msg") and process it as a CEF message.

Any sugestions?