sof-elk icon indicating copy to clipboard operation
sof-elk copied to clipboard

M365 UAL JSON Logs Not Parsed

Open joshlemon opened this issue 1 year ago • 7 comments

The M365 UAL JSON output from this tool (https://github.com/invictus-ir/Microsoft-Extractor-Suite) is not parsed correctly by the M365 parser in SOF-ELK.

FYI @invictus-ir @Pierre450

I'll also try to take a look at this and see if I can find out why it's not work too.

joshlemon avatar Aug 11 '23 06:08 joshlemon

Hi Josh, you may take a look at #264 , not sure if the fix would cover the changes (if any) happened over time

nightly-nessie avatar Aug 17 '23 17:08 nightly-nessie

The parser works in VM v20230529 but I confirmed that it's broken in v20230623. Phil is aware and will look at it when he has time.

Pierre450 avatar Aug 17 '23 18:08 Pierre450

The TCERT log collected works (although you have ti fix all the library dependencies), just not the Microsoft-Extractor-Suite

joshlemon avatar Aug 21 '23 02:08 joshlemon

The https://github.com/invictus-ir/Microsoft-Extractor-Suite generates UTF-16 encoded json files. This can be the problem.

marcottedan avatar Sep 05 '23 17:09 marcottedan

@joshlemon can you please send me a sample for this? I now have cycles to get this figured out. DM is fine of course.

philhagen avatar Nov 29 '23 01:11 philhagen

I've tested the parser on feature/ecs on a bunch of private sample data from @invictus-ir and with the usual exceptions of a very small number of inconsistent fields/data types, all seems to be working now. There was no BOM on the source data Korstiaan provided, so I am hopeful that possible edge case has been addressed upstream. I'm moving this one to "awaiting-validation" and it should see release (and issue close) with the next version

philhagen avatar Mar 11 '24 21:03 philhagen

I'm about to send a VM configured for testing this update and a TON of other changes to a small group. @marcottedan if you are interested in giving it a try, please send me an email: Phil at lewestech dot com.

philhagen avatar Apr 09 '24 22:04 philhagen