Skip to content

Add Cynet 360 XDR as a known vendor (CEF syslog) #2804

@morganfw

Description

@morganfw

Provide the new parser for Cynet 360 XDR out of the box, the syslog format is CEF.

What is the sc4s version?
3.38.0

Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?
No

What the vendor name?
Cynet

What's the product name?
Cynet 360 XDR

If you're requesting support for a new vendor, do you have any preferences regarding the default index and sourcetype for their events?
Index epintel
Sourcetype cynet:360:xdr:syslog

Do you have syslog documentation or a manual for that device??
https://help.cynet.com/en/articles/91-sending-syslog-to-3rd-party-siem
https://help.cynet.com/en/articles/144-how-to-send-syslog-to-ibm-security-qradar-siem

Feature Request description:
Provide the new parser for Cynet 360 XDR products out of the box

Do you want to have it for local usage or prepare a github PR?
Github PR

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions