Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Concatenate Fields for CEF output

$
0
0
ArcSight requires Microsoft-Windows-Security-Auditing:(EventCode) to properly categorize. What I am looking to do is like this: deviceEventClassId=Microsoft-Windows-Security-Auditing:($1) whereas `$1` is equal to EventCode so that Arcsight will import something like: Microsoft-Windows-Security-Auditing:5663

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>