Skip to content

Commit d86d129

Browse files
Merge pull request #234602 from oshezaf/asim/ref-to-source-by-source-type
Update normalization-manage-parsers.md
2 parents 83fbff1 + 0f35415 commit d86d129

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

articles/sentinel/normalization-manage-parsers.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -177,6 +177,8 @@ Some parsers requires you to update the list of sources that are relevant to the
177177
- Set the `SourceType` field to the parser specific value specified in the parser documentation.
178178
- Set the `Source` field to the identifier of the source used in the events. You may need to query the original table, such as Syslog, to determine the correct value.
179179

180+
If you system does not have the `Sources_by_SourceType` watchlist deployed, deploy the watchlist to your Microsoft Sentinel workspace from the Microsoft Sentinel [GitHub](https://aka.ms/DeployASimWatchlists) repository.
181+
180182
## <a name="next-steps"></a>Next steps
181183

182184
This article discusses managing the Advanced Security Information Model (ASIM) parsers.

0 commit comments

Comments
 (0)