We are trying to use the CEF integration to parse syslogs sent over from SentinelOne, but are getting an error message on processing which appears to be due to the date format.
Error - Text '2022-02-09 00:25:02,862' could not be parsed, unparsed text found at index 10
Is there a simple fix to parsing this correctly that I could try?
Also, any plans on adding the ability to specify an event dataset name other than cef, like with other integrations (UDP).
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.