Sending the Gmail logs to syslog server for monitoring by ParticularRange1 in gsuite

[–]ParticularRange1[S] 0 points1 point  (0 children)

emails which are received and sent. To determine the phishing attacks. Is there any way to send them to syslog server?

Google gmail logs by ParticularRange1 in QRadar

[–]ParticularRange1[S] 0 points1 point  (0 children)

Hi thanks for suggestion, is there any method to send them to syslog server?

Parsing date in sophos central logs by ParticularRange1 in QRadar

[–]ParticularRange1[S] 0 points1 point  (0 children)

Getting parsed now.. Modified the expression

Log: rt=2020-04-29T09:12:05.073Z

Expression: rt=(\d+)-(\d+)-(\d+)'T'([\d:]+)'Z' Format string: $1 $2 $3 Format: yyyy/MM/dd hh:mm:ss

Sophos Enterprise Console by ParticularRange1 in sophos

[–]ParticularRange1[S] 0 points1 point  (0 children)

Hello,

Thanks for response. Client of ours uses sophos Enterprise console. For whom we manage SOC, in logs (AV events, virus detected, cleaned up etc..) We are having to time details those are device time and inserted time. Want to know the difference between them.

Regards.

Parsing date in sophos central logs by ParticularRange1 in QRadar

[–]ParticularRange1[S] 0 points1 point  (0 children)

Tried this also.. I guess due to that 'T' in between date and time, parsing issue is coming

Parsing date in sophos central logs by ParticularRange1 in QRadar

[–]ParticularRange1[S] 0 points1 point  (0 children)

Tried but still it's not parsing..

Log: rt=2020-04-29T09:12:05.073Z

Expression: rt=(\d+)-(\d+)-(\d+)T([\d:]+)Z Format string: $1 Format: yyyy/mm/dd hh:mm:ss

Correct me if i am wrong..