Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Blason_R
Leader
Leader

What should be the settings for ingesting logs in SIEM for self managed spark devices

Hello,

If I need to ingest the and analyze the logs from spark 1500 series devices what should be a log type at SIEM end? it does not look like an CEF messages. It neither appears syslog messages , looks like those are KV pair messages?

Are those being sent using parsed method? Those are not being managed by centrally managed server and its standalone device.

 

 

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Not exactly sure what format Quantum Spark appliances export their data in that is relevant to SIEM.
I know it can't be changed.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events