Hello,
I have a Symantec Message Gateway log parsing problem and I choose to manually parse.
Symantec Message Gateway DSM is not supported by QRadara
Log example:
<142>Oct 4 15:42:03 mx2 bmserver[2537]: 1570189323|50538744-c7fff70000000aff-82-5d97300b77b1|VERDICT|test@test.com|none|default|default
<142>Oct 4 15:42:03 mx2 ecelerity[2815]: 1570189323|50538744-c7fff70000000aff-82-5d97300b77b1|ACCEPT|192.168.0.5:14173
Can you tell me please what regex cods do I need to use to parse |VERDICT| , test@test.com , |ACCEPT| , 192.168.0.5:14173 this values?
please, see attached log example
thank you
------------------------------
Davit Ubilava
System Administrator
Delta Consulting LLC
TbilisiGeorgia
------------------------------