Silver 1
Since ‎04-26-2024
7 hours ago

My Stats

  • 41 Posts
  • 6 Solutions
  • 16 Likes given
  • 23 Likes received

chrisd2's Bio

Badges chrisd2 Earned

View all badges

Recent Activity

Hello everyone,I have setup a Windows log collection via the Bindplane agent, everything is working fine. I just have one small issue with the logs : rawlog format is XML, it contains a key "RenderingInfo", that is useless and very verbose & that I w...
Hello guys,I'm trying to use the AS a given public IP is part of in the detection logic of a rule.I can see the metadata in the "Overview" results of the UDM search for a public IP (see entity.artifact.network.asn) :Issue :In my rule I'm trying to us...
Hello guys,I noticed that for some API endpoints, the URL path is : https://chronicle.googleapis.com/v1alpha/{api_version}/projects/{project_id}/locations/{region}/instances/{instance} (instances.get), but I could not figure out what the api_version ...
Hello everyone,I wrote a parser extension ("code" mode) for a log_type in order to add a couple fields that were not handled by the default parser.I mapped a couple raw fields to UDM fields under security_result in the parser ext.Problem: I noticed t...
Hello guys,Context :I'm working on some custom parsers for some logs that cannot be made native-SecOps-parsers-compliant. Once the parser is done, I need to validate it against a large number of logs. In order to do so, I export a few tens of thousan...
OSZAR »