splunk-connect-for-syslog icon indicating copy to clipboard operation
splunk-connect-for-syslog copied to clipboard

Zscaler NSS feed format tweaks for regex compliance for 'zscalernss-fw' & 'zscalernss-dns'

Open ducktailedplatypus opened this issue 3 years ago • 1 comments

The available default feed formats for ZScaler NSS sourcetypes 'zscalernss-fw' and 'zscalernss-dns' do not have the correct format OOTB to comply with the Zscaler NSS SC4S Source filter regex.

The date section of the 'named value pairs' output feed type for these specific feeds can be replaced with '%d{yy}-%02d{mth}-%02d{dd} %02d{hh}:%02d{mm}:%02d{ss}' (i.e. the format from the 'zscalernss-web' 'Splunk CIM' feed) to get it work again.

This is in addition to the currently documented addition of vendor and product fields to the end of the feed format.

Does the documentation need to the updated to include this feed change?

ducktailedplatypus avatar May 27 '21 12:05 ducktailedplatypus

yes can you make a pr for this?

ryanfaircloth avatar Jul 13 '21 13:07 ryanfaircloth

As there is no response on the issue, we are closing the issue.

rjha-splunk avatar Aug 29 '22 12:08 rjha-splunk