Support of Custom Properties parsing in Microsoft Windows Security Event Log DSM

The Microsoft Windows Security Event Log DSM supports Custom Event Properties parsing to extract additional properties from event payloads beyond standard normalized fields.

Overview

Custom Event Properties parsing enables the Microsoft Windows Security Event Log DSM to extract specific data fields from log events by using predefined regex patterns. Custom Event Properties parsing enhances event analysis by providing access to detailed information that might not be available in standard normalized event fields. Custom Event Properties parsing has the following key feature:
Configurable toggle
Custom Event Properties parsing can be enabled or disabled by using the isCEPEnabled parameter.

Configuration

Enabling Custom Event Properties parsing
Custom Event Properties parsing is enabled by default. To modify this setting, complete the following steps:
  1. Go to Admin > DSM Editor.
  2. Select Microsoft Windows Security Event Log DSM from the DSM list.
  3. Click the Configuration tab
  4. Go to DSM Parameters Configuration.
  5. Select Event Collector. Add or modify the following parameters:
    • Parameter Name: Enable CEP execution from the Microsoft Windows Security Event Log DSM
    • Value: Enable or disable
    Note: Updates to the Enable CEP Execution from the Microsoft Windows Security Event Log DSM parameter take effect immediately without requiring a restart of the event processor.
  6. Click Save and deploy the changes.
Disable Custom Event Properties Parsing

Enable Custom Properties Execution from the Microsoft Windows Security Event Log DSM is a toggle button and is enabled by default.

To disable Microsoft Windows Security Event Log DSM Custom Event Properties for the first time, complete the following steps:
  1. Select each Event Collector from the drop-down list one by one and disable the corresponding Event Collector.
  2. Click Save and deploy the changes.

You can enable or disable Custom Properties execution later for each Event Collector that is associated with the Microsoft Windows Security Event Log DSM.