I am receiving logs from MCAS in CEF format, can some one please help us what could be log source identifier to add a log source in QRadar...
Took referral URL : https://docs.microsoft.com/en-us/cloud-app-security/siem
Receiving logs as shown below:
Not capturing log source identifier information from the below, due to this unable to create new log source for MCAS...
Sample log : 2017-11-28T19:40:15.000Z CEF:0|MCAS|SIEM_Agent|0.112.68|EVENT_CATEGORY_VIEW_REPORT|View report|0|externalId=1511898027370_e272cd5f-31a3-48e3-8a6a-0490c042950a rt=1511898015000 start=1511898015000 end=1511898015000 msg=View report: ServiceNow Report 23 suser=adminSupport Member=ServiceNow dvc= requestClientApplication= cs1Label=portalURL cs1=https://contoso.portal.cloudappsecurity.com/#/audits?activity.id\=eq(1511898027370_e272cd5f-31a3-48e3-8a6a-0490c042950a,) cs2Label=uniqueServiceAppIds cs2=APPID_SERVICENOW cs3Label=targetObjects cs3=23,sys_report,adminSupport Member,adminSupport Member,adminSupport Member=policyIDs cs4= c6a1Label="Device IPv6 Address" c6a1=
#QRadar#Support#SupportMigration