scot icon indicating copy to clipboard operation
scot copied to clipboard

How to set Email Injest Parser module for Arcsight

Open johnuc opened this issue 4 years ago • 1 comments

Hello, The sample parser modules on the SCOT /opt/scot/lib/Scot/Parser/ does not have for ArcSight.

Can i adapt the parser for the splunk.pm. Do i need to make a change on the "parse_message” function" thanks

johnuc avatar Apr 09 '21 13:04 johnuc

I do not have access to ArcSight, so I'm afraid I can only provide rudimentary advise.

Splunk parser could definitely be used as a "template" to create your arcsight parser. There is also a "generic" and a "snort" parser included as well.

The concept is the same for all though. Read the email body, and create a data structure for an Alertgroup then return that.

toddbruner avatar Apr 26 '21 23:04 toddbruner