Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

CEF templates missing for feed.query.hit.binary and feed.query.hit.process event types

CEF templates missing for feed.query.hit.binary and feed.query.hit.process event types

Version
6.1.x


Issue

CEF templates missing for feed.query.hit.binary and feed.query.hit.process event types from from /usr/share/cb/syslog_templates

Symptoms
All other event types are being forwarded to your SIEM in CEF format except feed.query.hit.binary and feed.query.hit.process

Cause
Two syslog templates are missing from the /usr/share/cb/syslog_templates directory

Solution

Copy the feed.ingress.hit.binary and feed.ingress.hit.process templates over for the feed.query.hit.binary and feed.query.hit.process templates:

cp /usr/share/cb/syslog_templates/feed.ingress.hit.process.cef.template /usr/share/cb/syslog_templates/feed.query.hit.process.cef.template

cp /usr/share/cb/syslog_templates/feed.ingress.hit.binary.cef.template /usr/share/cb/syslog_templates/feed.query.hit.binary.cef.template




Labels (1)
Tags (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎10-23-2017
Views:
554
Contributors