-
Notifications
You must be signed in to change notification settings - Fork 120
Description
Provide the new parser for Cynet 360 XDR out of the box, the syslog format is CEF.
What is the sc4s version?
3.38.0
Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support?
No
What the vendor name?
Cynet
What's the product name?
Cynet 360 XDR
If you're requesting support for a new vendor, do you have any preferences regarding the default index and sourcetype for their events?
Index epintel
Sourcetype cynet:360:xdr:syslog
Do you have syslog documentation or a manual for that device??
https://help.cynet.com/en/articles/91-sending-syslog-to-3rd-party-siem
https://help.cynet.com/en/articles/144-how-to-send-syslog-to-ibm-security-qradar-siem
Feature Request description:
Provide the new parser for Cynet 360 XDR products out of the box
Do you want to have it for local usage or prepare a github PR?
Github PR