AnsweredAssumed Answered

NwLogDecoder Syslog Warning "Unidentified content from"

Question asked by David Mechsner on Jan 16, 2015
Latest reply on Jan 16, 2015 by David Mechsner

We try to send demo data from ArcSight to Security Analytics LogDecoder.

 

tcpdump shows that the logdecoder device receives the messages from network, but  NwLogDecoder don't decode it.

 

NwLogDecoder produces following warning in /var/log/messages:

 

Jan 16 11:49:00 LogDecoder nw[6462]: [SYSLOG] [warning] Unidentified content from xxx.xxx.xxx.xxx received on receiver: 'CEF:0|Test|Test|Test|Test|Test|Test|Test'

 

Could anyone help?

Outcomes