Forum Discussion

KB13_332644's avatar
KB13_332644
Icon for Nimbostratus rankNimbostratus
Sep 15, 2017

Modify ArcSight log format

Anyone know if it is possible to modify the ArcSight logging format for ASM logs? Would like to throw the Host header value into destinationHostName, but I'm unsure if it's possible to modify the canned CEF structure.

 

Thanks!

 

-Kevin

 

2 Replies

  • The format is pre-defined and unfortunately can not be changed.

     

    K16702: The remote logging format for ArcSight and Reporting Server remote storage types

     

    The storage format for the syslog option can be configured:

     

    K9435: Overview of the Storage Format option for a remote logging profile