This is the standard CEF format:
CEF:0|Vendor|Product|Version|ID|Name|Severity|Extension
but ELSA parses it as:
CEF:0|Version|Vendor|Product|ID|Name|Severity|Extension
Attached there is a simple patch.
Regards,
-- Andrea De Pasquale
Original issue reported on code.google.com by and...@de-pasquale.name on 4 Sep 2013 at 3:14
Original issue reported on code.google.com by
and...@de-pasquale.name
on 4 Sep 2013 at 3:14Attachments: