Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Need to extract top web users from TMG logs using LEM

$
0
0

Hi Hanif,

 

I checked with the LEM connectors team and here are the fields we currently normalize for the most common events:

 

  • r-host - Host
  • s-operation - operation
  • sc-status - status
  • rule - Rule
  • c-ip - SourceMachine
  • r-ip - DestinationMachine
  • s-computername - DetectionIP
  • s-port - SourcePort
  • r-port - DestinationPort
  • cs-protocol -  Protocol
  • cs-uri - URL
  • UrlCategory - Category
  • cs-userName – SourceAccount

 

As you can see, "bytes" is not included.

 

Two things:

  1. Without the bytes field present, we can only go by the number of accesses to different URLs per user.
  2. Even if the bytes field were present in the event, there are no reports in LEM that accumulate bytes to create this type of report. It MIGHT be possible to do so with a full version of Crystal Reports (if we were to add the bytes to the event somewhere), but we don't have anything that does this today. LEM reports are strictly based on event counts.

Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>