Symantec Endpoint Protection サンプル・イベント・メッセージ

このサンプル・イベント・メッセージは、 IBM QRadarとの統合が正常に行われたことを確認するために使用します。

重要: フォーマットの問題のため、メッセージ・フォーマットをテキスト・エディターに貼り付けてから、復帰文字または改行文字を削除してください。

Syslog プロトコルを使用する場合の Symantec Endpoint Protection サンプル・メッセージ

以下のサンプル・イベント・メッセージは、ファイアウォール・ブロックを示しています。

<51>Oct 3 23:51:53 symantec.endpointprotection.english.test SymantecServer: 20-11111A111111,Event Description: The client will block traffic from IP address 10.33.146.1 for the next 60 seconds (from 03/10/2019 23:51:04 to 03/10/2019 23:52:04). ,Local: 10.246.162.238,Local Host MAC: 000000000000,Remote Host Name: ,Remote Host IP: 10.33.146.1,Remote Host MAC: 000000000000,Inbound,OTHERS,,Begin: 2019-10-03 23:51:04,End: 2019-10-03 23:52:04,Occurrences: 1,Application: ,Location: Test Loc - VPN,User: A1111111,Domain: TESTDOMAIN,Local Port: 0,Remote Port: 0,CIDS Signature ID: 0,CIDS Signature string: ,CIDS Signature SubID: 0,Intrusion URL: ,Intrusion Payload URL: ,SHA-256: ,MD-5:
表 1. QRadar イベント・ペイロード内のフィールド名と強調表示された値
QRadarフィールド名 イベント・ペイロードで強調表示される値
イベント ID Event Description (ファイアウォール・ブロックを抽出)
送信元 IP 10.33.146.1
宛先 IP 10.246.162.238
Username A1111111
デバイス時刻 2019-10-03 23:51:04