You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It would be nice if the CEF parser would recover from errors detected in the CEF header and try to resume parsing the CEF extensions. For example the header on this message is incomplete, but the remainder of the CEF extensions are good.
The expected behavior is that there would be an error.message in the event because the message is not valid per the spec, but all of the cef.extension values would be present. This is what you get today.
andrewkroh
changed the title
[Filbeat] decode_cef - recover from errors in the CEF header
[Filebeat] decode_cef - recover from errors in the CEF header
Mar 9, 2022
It would be nice if the CEF parser would recover from errors detected in the CEF header and try to resume parsing the CEF extensions. For example the header on this message is incomplete, but the remainder of the CEF extensions are good.
Feb 11 19:12:22 ec2-54-211-162-22 2022-02-11 19:12:22,962 sentinel - CEF:0|SentinelOne|Mgmt|activityID=1111111111111111111 activityType=3505 siteId=None siteName=None accountId=1222222222222222222 accountName=foo-bar mdr notificationScope=ACCOUNT
The expected behavior is that there would be an
error.message
in the event because the message is not valid per the spec, but all of thecef.extension
values would be present. This is what you get today.The text was updated successfully, but these errors were encountered: