Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to modify default fields in Trend Micro Deep Security for Splunk?

$
0
0
Hi, I'm receiving syslog flow from Trend Micro Deep Security. After installing the app for Splunk, I would like to check how the fields are populate by it. I've got an issue with the field "DPI_Reason", where I can find the Trend Micro rule number. The field in the raw data is, for example, "502", but the field in splunk is "-502". And it only populate the field with default values like 502 or 504, not with custom rules like 1001234. Thanks Max

Viewing all articles
Browse latest Browse all 47296

Trending Articles