Support of Custom Properties parsing in Microsoft Windows Security Event Log DSM
The Microsoft Windows Security Event Log DSM supports Custom Event Properties parsing to extract additional properties from event payloads beyond standard normalized fields.
Overview
Custom Event Properties parsing enables the Microsoft Windows Security Event Log DSM to extract
specific data fields from log events by using predefined regex patterns. Custom Event Properties
parsing enhances event analysis by providing access to detailed information that might not be
available in standard normalized event fields. Custom Event Properties parsing has the following key feature:
- Configurable toggle
- Custom Event Properties parsing can be enabled or disabled by using the isCEPEnabled parameter.
Configuration
- Enabling Custom Event Properties parsing
- Custom Event Properties parsing is enabled by default. To modify this setting, complete the
following steps:
- Go to Admin > DSM Editor.
- Select Microsoft Windows Security Event Log DSM from the DSM list.
- Click the Configuration tab
- Go to DSM Parameters Configuration.
- Select Event Collector. Add or modify the following parameters:
- Parameter Name: Enable CEP execution from the Microsoft Windows Security Event Log DSM
- Value: Enable or disable
Note: Updates to the Enable CEP Execution from the Microsoft Windows Security Event Log DSM parameter take effect immediately without requiring a restart of the event processor. - Click Save and deploy the changes.
- Disable Custom Event Properties Parsing
Enable Custom Properties Execution from the Microsoft Windows Security Event Log DSM is a toggle button and is enabled by default.
To disable Microsoft Windows Security Event Log DSM Custom Event Properties for the first time, complete the following steps:- Select each Event Collector from the drop-down list one by one and disable the corresponding Event Collector.
- Click Save and deploy the changes.
You can enable or disable Custom Properties execution later for each Event Collector that is associated with the Microsoft Windows Security Event Log DSM.