elastic / elastic/integrations

Cisco Secure Email Gateway | Use CEF processor instead of GROK for Consolidated Event logs

Open
#4,738 5 comments 0 reactions 0 assignees View on GitHub
enhancement Integration:cisco_secure_email_gateway Stalled Team:Security-Deployment and Devices
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
2d 17h
Merged PRs (30d)
225

Description

Currently, `cisco_secure_email_gateway` uses GROK to parse consolidated event logs. Since these consolidated logs are in Common Event Format (CEF), we could use `cef` processor instead to improve parsing performance.

Reference - [Consolidated Event Logs](https://www.cisco.com/c/en/us/td/docs/security/ces/user_guide/esa_user_guide_14-0-2/b_ESA_Admin_Guide_ces_14-0-2/b_ESA_Admin_Guide_12_1_chapter_0100111.html#:~:text=with%20AsyncOS%20API-,Consolidated%20Event%20Logs,-The%20Consolidated%20Event)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.