Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Explorer

fields mapping in LeefFieldsMapping.xml

Hi there,

 

I just noticed that "cat" field maps to "action" field in the documentation. Should it be mapping to "product" field if it's for QRadar LEEF format? And should "action" map to EventID instead? Could you please confirm that? Thanks.

0 Kudos
Reply
1 Reply
Highlighted

Hi,

It's a good question. Wasn't involved in the mapping, but from IBM's description think it makes sense to map action to cat as to extend EventID with additional information about the event. It may also get mapped to EventID. In the header we map product and EventID like this.

Product: the assign_order is set to first

This default is Log Update, but may also be the value from the fields; product or productname.

Event ID, the assign_order is set to init

The default is Check Point Log, but may also be the value from the fields protection_name, appi_name, action.


Expect the end result would be something like their Example 1. 

https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/c_LEEF_Format_Guide_predefinedAttrrs.html 

0 Kudos
Reply