Cisco-AMP / amp4e_splunk_cim_add_on

BSD 2-Clause "Simplified" License
2 stars 9 forks source link

event_type_id missing in mapping file #1

Closed ThomasMethlie closed 7 years ago

ThomasMethlie commented 7 years ago

Is it possible to add event_type_id 1090519054 to the .csv file mapping? Now a lot of searches in ES returns empty results.

samsonnguyen commented 7 years ago

Hi @ThomasMethlie ,

are you able to provide more details? Specifically:

Symptoms observed in Splunk Steps to reproduce Expectations

ThomasMethlie commented 7 years ago

Hi @samsonnguyen , I seem to have made some sort of mistake but I'm now able to see the events in Splunk with "unkown" action status, which seems to be correct according to the CIM model. Sorry for troubling you. (The malware had status "quarantine:failed" in amp dashboard, not blocked as I originally thought).