IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CEF templates missing for feed.query.hit.binary and feed.query.hit.process event types

CEF templates missing for feed.query.hit.binary and feed.query.hit.process event types

Version
6.1.x


Issue

CEF templates missing for feed.query.hit.binary and feed.query.hit.process event types from from /usr/share/cb/syslog_templates

Symptoms
All other event types are being forwarded to your SIEM in CEF format except feed.query.hit.binary and feed.query.hit.process

Cause
Two syslog templates are missing from the /usr/share/cb/syslog_templates directory

Solution

Copy the feed.ingress.hit.binary and feed.ingress.hit.process templates over for the feed.query.hit.binary and feed.query.hit.process templates:

cp /usr/share/cb/syslog_templates/feed.ingress.hit.process.cef.template /usr/share/cb/syslog_templates/feed.query.hit.process.cef.template

cp /usr/share/cb/syslog_templates/feed.ingress.hit.binary.cef.template /usr/share/cb/syslog_templates/feed.query.hit.binary.cef.template




Labels (1)
Tags (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎10-23-2017
Views:
770
Contributors