Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Need update for Parser for Symantec Endpoint Protection and CrowdStrike Falcon Endpoint Protection Connector #9420

Closed
AllyDao opened this issue Nov 20, 2023 · 20 comments
Assignees
Labels
Connector Connector specialty review needed Parser Parser specialty review needed

Comments

@AllyDao
Copy link

AllyDao commented Nov 20, 2023

Is your feature request related to a problem? Please describe.
For CrowdStrike Falcon Endpoint Protection , the log severity in the original parser, there are 5, however, the result when I search, there is even more than 5 which is 10,28,63. Moreover, the message of the log severity 5 is the same as the log severity 2 which should not be.

For Symantec Endpoint Protection, the parser is not doing well as in OOTB use cases for Symantec, they have log type, and I don't get that information.

Describe the solution you'd like
Please information why for this happening and if I need to update my parser, if needed, please inform me the steps

Describe alternatives you've considered
A clear and concise description of any alternative solutions or features you've considered.
n/a

Additional context

I cannot add screenshot to this when create case, if you have any concern, please reach me via my Teams : v-daohiep@microsoft.com

Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@v-amolpatil v-amolpatil added the Connector Connector specialty review needed label Nov 20, 2023
@v-sudkharat v-sudkharat added the Parser Parser specialty review needed label Nov 20, 2023
@v-muuppugund
Copy link
Contributor

Hi @AllyDao , Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 22Nov23. Thanks!

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,Could you please share more details about the issue with logs and screen shots trying to reach over teams for the same,Thanks.

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,As discussed yesterday evening over team's call, got the details on issues, will work on it and get back to you with an update.

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,Currently working on replicating the issue and once replicates, will work on changes, will post updates by 29Nov23

@AllyDao
Copy link
Author

AllyDao commented Dec 5, 2023

Hi, I am still waiting for the information from your team

@AllyDao
Copy link
Author

AllyDao commented Dec 13, 2023

Hi, why there is no update on this issue ?

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,Please check the attached updated Symantec parser from team,mean while trying to replicate the crowdstrike issue and will update you
updated Symantec Parser.txt

@v-muuppugund
Copy link
Contributor

v-muuppugund commented Dec 19, 2023

Hi @AllyDao ,As discussed over teams, please schedule call with customer for the Symantec parser issue, as we don't have data for CrowdStrike issue, checking workspaces and modifying the query.

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,As discussed over teams chat, shared both Symantec and CrowdStrike parsers, we need to test it as we don't have data, so please schedule call with customer,Thanks.

@v-muuppugund
Copy link
Contributor

v-muuppugund commented Dec 22, 2023

Hi @AllyDao ,
The following are done on this issue.

  • As discussed on 20/12 with customer on call, after Crowd strike parser changes tested at customer environment and it's working as expected, please let me know if any issues
  • As discussed on yesterday with customer on call, Symantec end point protection parser still having issue and has provided data yesterday, will be working on it

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,working on parser testing ,once done,will update you

@v-muuppugund
Copy link
Contributor

Hi @AllyDao , Still working on parser testing, will update you.

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,I have blocked time on monday for Symantic parser testing with customer as load testing still going on.

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,As discussed over teams yesterday ,asked to reschedule to today as per customer request,so rescheduled meeting today.

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,As discussed today over call,shared the updated Symantec parser and got the log types parsed from parser,sharing the below screen shot for reference,
image
There are data missing for these log type and asked for data

  1. Admin logs
  2. System logs
  3. Risk Logs

Got the logs over email today after call,Will analyze the shared data and update the parser ,test and share V2 version

@v-muuppugund
Copy link
Contributor

v-muuppugund commented Jan 21, 2024

Hi @AllyDao ,As discussed on 16Jan24,Shared the initial version of parser as the above log types are missing as don't have data,got the data on 16Jan24,so completed the analysis and working on changes,will update you for v2 version.

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,Blocked calendar with customer next week for symantic parser final version ,meanwhile testing it if find had any queries related to data will reach

@v-muuppugund
Copy link
Contributor

Hi @AllyDao ,As discussed over teams,scheduled call tomorrow for the Symantec parser testing.

@v-muuppugund
Copy link
Contributor

v-muuppugund commented Feb 1, 2024

Hi @AllyDao ,As discussed over call, customer tested the parser and will be monitoring couple of days, will reach me if any issues, as both the parsers are resolved, so closing this issue (#9420) . and will be working on PR's next steps after couple of days,If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed Parser Parser specialty review needed
Projects
None yet
Development

No branches or pull requests

4 participants