Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

????????? #10455

Closed
vincentche1 opened this issue May 8, 2024 · 11 comments
Closed

????????? #10455

vincentche1 opened this issue May 8, 2024 · 11 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@vincentche1
Copy link

vincentche1 commented May 8, 2024

No description provided.

@v-sudkharat v-sudkharat added the Connector Connector specialty review needed label May 9, 2024
@v-sudkharat
Copy link
Contributor

Hi @vincentche1, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 16-05-2024. Thanks!

@vincentche1
Copy link
Author

Dear @v-sudkharat, I hope you can expedite faster as the problem is impacted customer workflow. Please inform me if you need further details for investigation.
The parser of Trend Micro Apex One CEF logs link: https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/Trend%20Micro%20Apex%20One/Parsers/TMApexOneEvent.yaml

@v-sudkharat
Copy link
Contributor

@vincentche1, Sure, and Thanks for providing details.

@vincentche1
Copy link
Author

Hi @v-sudkharat, we hope that you can expedite this issue as it is pending for a remarkable time

@v-sudkharat
Copy link
Contributor

Hi @vincentche1, we were unable to address this issue because of our lack of availability. we'll investigate on it and give you an update by 25-05-2024. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @vincentche1, Just want to check below few points with your end: -

  1. As per your give description, Your facing issue in step C. where data is not received into the CommonSecurityLog table, Is that correct?
    image

  2. Could you please check and let us know what is "streams" name for existing created Data Collection Rule? Please share the JSON view with us if possible: -
    image

  3. Could you please validate and let us know the below configuration has been done in Azure and Apex portal which mentioned in steps A and B: -
    image

Thanks!

@v-sudkharat
Copy link
Contributor

@vincentche1, Ok. Noted. Let us check and will update you.

@MeirLevinMicrosoft
Copy link
Contributor

@vincentche1 from the log sample you sent. It seems like the log header is not compliant with CEF:
image

https://www.microfocus.com/documentation/arcsight/arcsight-smartconnectors-8.4/pdfdoc/cef-implementation-standard/cef-implementation-standard.pdf

Try removing "tmes[1]:" from the log header.

Also, I think the log date format is also not compliant, but this should not stop the logs from being ingested but might be resulted in inconsistency between the actual log timestamp and CommonSecurityLog timestamp.

@MeirLevinMicrosoft
Copy link
Contributor

In case you don't get even mock messages it's not a formatting issue. I suggest:

  1. Make sure you have latest agent version
  2. Execute CEF troubleshooter:
    sudo wget -O Sentinel_AMA_troubleshoot.py https://raw.githubusercontent.com/Azure/Azure-sudo wget -O Sentinel_AMA_troubleshoot.py https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/Syslog/Sentinel_AMA_troubleshoot.py && sudo python3 Sentinel_AMA_troubleshoot.py&& sudo python3 Sentinel_AMA_troubleshoot.py

Please note the formatting issue remains IMO, so once you get the mock messages you will still need to fix it.
Also, for further assistance I suggest open a ticket to Azure Sentinel as more data is required to understand the root cause.

@vincentche1
Copy link
Author

Dear @MeirLevinMicrosoft @v-sudkharat , could you let me is there any update or any info you need to check more?

@v-sudkharat
Copy link
Contributor

v-sudkharat commented May 28, 2024

Requesting for follow procedure. Thanks!

@vincentche1 vincentche1 changed the title Trend Micro Apex One cannot ingest some kinds of CEF log into Sentinel ????????? May 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

4 participants