Hi
Anyone using DLC (Disconnected Log Collector) ? I am trying to test the log source configuration on DLC 1.4.0. And somehow I am failing on validation of the JSON file. I tried to create it by hand (coping from template) but also created it using Log Source Management App and tried to import. In both cases I run into an error:
2020-Jul-27 12:31:16.724 ERROR - "SMB Tail" does not belong the schema.
2020-Jul-27 12:31:16.724 ERROR - The logsource 1 fail the validation.
Do I need to install some RPMs on the DLC? Or what is going on?
#QRadar#Support#SupportMigration