Skip to content

Commit bee17d3

Browse files
Merge pull request #280175 from haim-na/haim-na/update-unified-connector-syslog-device
Update parser instructions - unified-connector-syslog-device
2 parents e599cf2 + aaf0e63 commit bee17d3

File tree

1 file changed

+9
-9
lines changed

1 file changed

+9
-9
lines changed

articles/sentinel/unified-connector-syslog-device.md

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ This data connector was developed using Cisco Stealthwatch version 7.3.2
6262
> [!NOTE]
6363
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
6464
>
65-
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's second line.
65+
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
6666
>
6767
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **CiscoUCS**. Alternatively, directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cisco%20UCS/Parsers/CiscoUCS.txt). It might take about 15-minutes post-installation to update.
6868
@@ -240,7 +240,7 @@ Complete the following steps.
240240
> [!NOTE]
241241
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
242242
>
243-
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's second line.
243+
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
244244
>
245245
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **PulseConnectSecure**. Alternatively, directly load the [function code](https://aka.ms/sentinel-PulseConnectSecure-parser). It might take about 15 minutes post-installation to update.
246246
@@ -252,7 +252,7 @@ Complete the following steps to get RSA® SecurID Authentication Manager logs in
252252
> [!NOTE]
253253
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
254254
>
255-
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's second line.
255+
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
256256
>
257257
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **RSASecurIDAMEvent**. Alternatively, you can directly load the [function code](https://aka.ms/sentinel-rsasecuridam-parser). It might take about 15 minutes post-installation to update.
258258
@@ -266,7 +266,7 @@ This data connector was developed using RSA SecurID Authentication Manager versi
266266
> [!NOTE]
267267
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
268268
>
269-
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's second line.
269+
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
270270
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **SophosXGFirewall**. Alternatively, directly load the [function code](https://aka.ms/sentinel-SophosXG-parser). It might take about 15 minutes post-installation to update.
271271
272272

@@ -278,7 +278,7 @@ This data connector was developed using RSA SecurID Authentication Manager versi
278278
> [!NOTE]
279279
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
280280
>
281-
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's second line.
281+
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
282282
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **SymantecEndpointProtection**. Alternatively, you can directly load the [function code](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/Symantec%20Endpoint%20Protection/Parsers/SymantecEndpointProtection.yaml). It might take about 15 minutes post-installation to update.
283283
284284
## Symantec ProxySG
@@ -298,7 +298,7 @@ This data connector was developed using RSA SecurID Authentication Manager versi
298298
> [!NOTE]
299299
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
300300
>
301-
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's second line.
301+
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
302302
>
303303
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **SymantecProxySG**. Alternatively, directly load the [function code](https://aka.ms/sentinel-SymantecProxySG-parser). It might take about 15 minutes post-installation to update.
304304
@@ -309,7 +309,7 @@ This data connector was developed using RSA SecurID Authentication Manager versi
309309
> [!NOTE]
310310
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
311311
>
312-
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's second line.
312+
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
313313
>
314314
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias **SymantecVIP**. Alternatively, directly load the [function code](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Symantec%20VIP/Parsers/SymantecVIP.txt). It might take about 15 minutes post-installation to update.
315315
@@ -325,7 +325,7 @@ This data connector was developed using RSA SecurID Authentication Manager versi
325325
> [!NOTE]
326326
> The functionality of this data connector is reliant on a Kusto Function-based parser, which is integral to its operation. This parser is deployed as part of the solution installation.
327327
>
328-
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's second line.
328+
> Update the parser and specify the hostname of the source machines transmitting the logs in the parser's first line.
329329
>
330330
> To access the function code within Log Analytics, navigate to the Log Analytics/Microsoft Sentinel Logs section, select Functions, and search for the alias VMwareESXi. Alternatively, directly load the [function code](https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Solutions/VMWareESXi/Parsers/VMwareESXi.yaml). It might take about 15 minutes post-installation to update.
331331
@@ -336,4 +336,4 @@ This data connector was developed using RSA SecurID Authentication Manager versi
336336
## Related content
337337

338338
- [Ingest syslog and CEF messages to Microsoft Sentinel with the Azure Monitor Agent](connect-cef-syslog-ama.md)
339-
- [Syslog via AMA and Common Event Format (CEF) via AMA connectors for Microsoft Sentinel](cef-syslog-ama-overview.md)
339+
- [Syslog via AMA and Common Event Format (CEF) via AMA connectors for Microsoft Sentinel](cef-syslog-ama-overview.md)

0 commit comments

Comments
 (0)