Closed GoogleCodeExporter closed 9 years ago
This is a problem with the parser not being specific to the myriad of types of
Windows messages. The "source" field works on some but not others. At some
point, I'd like to define much more specific parsers for a lot of Windows logs,
especially to pull out usernames and "network source" addresses (IP's).
Patterns are welcome! To quickly get started, check out the patternize utility
(http://gyp.blogs.balabit.com/tag/patternize/), which will take a file full of
logs (which you can get by doing an export from ELSA) and will find all of the
similar and non-similar patterns to ease patterndb writing.
Original comment by mchol...@gmail.com
on 23 Feb 2012 at 5:37
Closing until I or other write patterns for these.
Original comment by mchol...@gmail.com
on 31 May 2012 at 2:45
Original issue reported on code.google.com by
edavi...@gmail.com
on 23 Feb 2012 at 4:52