Skip to content

Bug in barracuda_waf parser #2796

@ehlo550

Description

@ehlo550

What is the sc4s version ?
3.37.0

Describe the bug
As mentioned in the slack community.
When trying to onboard syslogs from Cisco CIMC the logs are identified as barracuda_waf due to the program being AUDIT.

Sample Log from Cisco CIMC:

<37>Sep 16 10:51:14 hostname001 AUDIT[2386]: Login failed (ip:192.168.12.230, service:webgui) due to invalid password

Splunk Case: 3852195

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions