Hi Jon,
thanks for your answer.
I have already replied this way to the ArcSight team too, to be sure I wanted confirmation from the community. :)
Just a curiosity, to send the WebSEAL (reverse Proxy) logs in that format just insert these entries in the configuration file, for example:
[logging]
server-log-cfg = file path = msg__webseald-default.log, hi_water = 1, flush_interval = 20, rollover_size = 90000000, max_rollover_files = 20
[aznapi-configuration]
logcfg = http.clf: stdout hi_water = 1, flush_interval = 1, queue_size = 50
logcfg = http.clf: file path = request.log, flush = 10, rollover = 1000000, max_rollover_files = 10, log = request, buffer_size = 8192, queue_size = 48, log_id = request
?
Thanks a lot,
Claudio
------------------------------
Claudio Laganà
------------------------------
Original Message:
Sent: Thu June 03, 2021 05:27 AM
From: Jon Harry
Subject: Audit log format
Hi Claudio,
Looking at the two log examples you've provided, it looks as though the first one is from our AAC Runtime and the second is from our Reverse Proxy. If Arcsight is expecting the second format, perhaps you're sending the wrong audit logs?
If your issue is that you want to receive logs from AAC Runtime in the same format as those from the Reverse Proxy, I don't think that it's possible to change the format of our audit messages. In that case, I would have thought that it was usual for the SIEM solution to perform required mapping for received messages (rather than expecting product to output logs in some prescribed format). IBM's QRadar SIEM certainly has this capability. It has a DSM for each supported source with the rules required to process audit entries from that source.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------