Custom Log Ingestion
Custom log ingestion was introduced in Juniper Advanced Threat Prevention software release version 5.0.4.
About Custom Log Ingestion
Custom Log Ingestion Overview
The custom log ingestion feature lets you create your own log parsers on the ATP Appliance appliance using sample logs you provide. This way, if you want to use logs from a vendor not supported by existing ATP Appliance log parsers, you can do so. By mapping fields in your sample logs to ATP Appliance event fields, you build your own custom parser, indicating which types of events will generate an incident. You can also view statistics on incoming logs and delete collected logs.
Configure the Log Parser
Use the following procedure to create your own custom log parser.
When you are finished configuring your custom log parser, the filters you created are combined to save only the logs you indicated with a threat level setting based on the criteria you configured.
Use the Log Parser
After you configure the custom log parser, you must apply it to the ATP Appliance Event Collector.
Custom Log Statistics
When an External Event Collector is created for a custom log, counters are displayed in the External Event Collector page for that log source. The information displayed in the counter is the number of logs collected over 5 minutes, 1 hour, 1 day, 1 week intervals, and a total count, broken down by the fields you chose when creating the custom log parser.
Logs statistic may include the following:
All Incoming Logs: Aggregate (lifetime), Last 5 minutes, Last 1 hour, Last 24 hours, and Last 7 days
All Created Events: Aggregate(lifetime), Last 5 minutes, Last 1 hour, Last 24 hours, and Last 7 days
Parsed field counts (user selected for counting): From incoming logs, each value that appears is displayed, along with the number of times it has occurred in aggregate (lifetime) - last week, last day, last hour, and last 5 minutes.
From the External Event Collector page, click the Counters link to view log statistics.