Andrew T

Results 4 issues of Andrew T

**Describe the bug** When the `vimAuditEventMicrosoftSecurityEvents` or `ASimAuditEventMicrosoftSecurityEvents` return parsers results for Scheduled Task Events. The Value/NewValue field contains improperly unescaped XML which can not be parsed with parse_xml. The...

ASIM

**Describe the bug** When running vimAuditEventMicrosoftSecurityEvents, Events related to Scheduled Task information results are missing the Value, NewValue, Object and ObjectType fields. These fields are present when running ASimAuditEventMicrosoftSecurityEvents When...

ASIM

Required items, please complete Change(s): - Updated vimAuditEventMicrosoftSecurityEvents.yaml to include additional fields - Updated vimAuditEventMicrosoftSecurityEvents.yaml to correctly unescape TaskContent XML - Updated ASimAuditEventMicrosoftSecurityEvents.yaml.yaml to correctly unescape TaskContent XML Reason for...

ASIM

I am working on implementing Sentinel for a new customer which is using Cisco ISE, and we would like to make use of the Cisco ISE Solution. However we are...

Hunting