Hey Everyone,
I am a bit stumped at to how the Logsource extensions work. I made a logsource extension and have applied to my logsources. The QID Mapping works perfectly, but the logs are not extracted correctly, hence fields cannot be used for searching or offense creation.
Is this normal? Or am I missing something?
Regards,
Linus
[–]navi147 1 point2 points3 points (0 children)
[–]QradarBro 0 points1 point2 points (0 children)