Skip to content

Conversation

@Caleb-Hurshman
Copy link
Contributor

Description

Adds a new OTTL func to parse LEEF format log data.

Link to tracking issue

Fixes #44908, also mentioned in #37442

Testing

Adds unit testing for LEEF format logs, including sample event messages provided by IBM to ensure integration with QRadar:
https://www.ibm.com/docs/en/dsm?topic=guardium-sample-event-messages

Documentation

Updates the OTTL function readme, changelog entry added.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[pkg/ottl] Add LEEF log parser

2 participants