diff --git a/package/etc/conf.d/conflib/_common/templates.conf b/package/etc/conf.d/conflib/_common/templates.conf index cc49e3b..bf8a218 100644 --- a/package/etc/conf.d/conflib/_common/templates.conf +++ b/package/etc/conf.d/conflib/_common/templates.conf @@ -31,7 +31,7 @@ template t_msg_trim { # =============================================================================================== template t_everything { - template("${ISODATE} ${HOST} ${MSGHDR}${MESSAGE}"); + template("${ISODATE} ${HOST} ${LEGACY_MSGHDR}${MESSAGE}"); }; # =============================================================================================== diff --git a/package/etc/conf.d/context/common_event_format_source.csv b/package/etc/conf.d/context/common_event_format_source.csv index d668350..1aaa666 100644 --- a/package/etc/conf.d/context/common_event_format_source.csv +++ b/package/etc/conf.d/context/common_event_format_source.csv @@ -1,4 +1,6 @@ ArcSight_ArcSight,source,ArcSight:ArcSight +Carbon Black_Protection,sourcetype,carbonblack:protection:cef +Carbon Black_Protection,index,cb:cef Cyber-Ark_Vault,sourcetype,cyberark:epv:cef Cyber-Ark_Vault,index,netauth CyberArk_PTA,sourcetype,cyberark:pta:cef @@ -9,4 +11,4 @@ Microsoft_Microsoft Windows,source,CEFEventLog:Microsoft Windows Microsoft_Microsoft Windows,index,oswinsec Incapsula_SIEMintegration,source,Imperva:Incapsula Incapsula_SIEMintegration,index,netwaf -unknown,source,ArcSight:unknown +unknown,source,CEF:unknown diff --git a/package/etc/conf.d/filters/cisco/ios.conf b/package/etc/conf.d/filters/cisco/ios.conf index 0a2667e..4b7f995 100644 --- a/package/etc/conf.d/filters/cisco/ios.conf +++ b/package/etc/conf.d/filters/cisco/ios.conf @@ -9,26 +9,30 @@ parser cisco-parser-ex{ channel { filter { #message('^<\d*>(?:(?\d+)\: )?(?:(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}|([a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9\-]*[a-zA-Z0-9])\.)*([A-Za-z0-9]|[A-Za-z0-9][A-Za-z0-9\-]*[A-Za-z0-9]): )?(?:(?\d+): )?(?:(?\*)?(?(?