Support of Custom Properties parsing in Linux OS DSM

The Linux OS DSM supports Custom Event Properties parsing to extract additional properties from event payloads beyond standard normalized fields.

Overview

Custom Event Properties parsing enables the Linux OS DSM to extract specific data fields from log events by using predefined regex patterns. Custom Event Properties parsing enhances event analysis by providing access to detailed information that might not be available in standard normalized event fields. Custom Event Properties parsing has following key feature:
Configurable toggle
Custom Event Properties parsing can be enabled or disabled by using the isCEPEnabled parameter.

Configuration

Enabling Custom Event Properties parsing
Custom Event Properties parsing is enabled by default. To modify this setting, complete the following steps:
  1. Go to Admin > DSM Editor.
  2. Select Linux OS from the DSM list.
  3. Click the Configuration tab
  4. Go to DSM Parameters Configuration.
  5. Check Display DSM Parameters Configuration
  6. Select Enable CEP Execution from the Linux DSM.
    Note: Enable CEP Execution from the Linux OS DSM is a toggle button and is enabled by default.
  7. Click Save and deploy the changes.
Disable Custom Event Properties Parsing
To disable Linux OS DSM Custom Event Properties for the first time, complete the following steps:
  1. Select each Event Collector from the drop-down list one by one and disable the corresponding Event Collector.
  2. Click Save and deploy the changes.
Note:

You can enable or disable Custom Event Properties execution later for each Event Collector that is associated with the Amazon AWS CloudTrail DSM.

Changes to the Enable CEP execution from the Linux OS DSM parameter take effect immediately without requiring a restart of the event processor.