<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyone using Common Event Format (CEF) with Dynatrace? in Log Analytics</title>
    <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215884#M423</link>
    <description>&lt;P&gt;I took a CEF example from &lt;A href="https://support.citrix.com/article/CTX136146/common-event-format-cef-logging-support-in-the-application-firewall" target="_self"&gt;this page&lt;/A&gt;&amp;nbsp;then used &lt;A href="https://agardnerit.github.io/logpusher" target="_self"&gt;logpusher&lt;/A&gt;&amp;nbsp;to send it to Dynatrace via an OpenTelemetry collector. (&lt;A href="https://www.youtube.com/watch?v=BzkzmzPdW5M" target="_self"&gt;see this video for how to use logpusher&lt;/A&gt;).&lt;BR /&gt;&lt;BR /&gt;I then used DQL to filter my incoming log lines:&lt;BR /&gt;&lt;BR /&gt;fetch logs, scanLimitGBytes: 1&lt;BR /&gt;| filter matchesPhrase(content, "act=blocked")&lt;BR /&gt;| sort timestamp desc&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2023 05:33:11 GMT</pubDate>
    <dc:creator>adam_gardner</dc:creator>
    <dc:date>2023-06-23T05:33:11Z</dc:date>
    <item>
      <title>Anyone using Common Event Format (CEF) with Dynatrace?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/214099#M420</link>
      <description>&lt;P&gt;Common Event Format (CEF) is an open logging and auditing format, that is quite used in the SIEM market. Being able to send events&amp;amp;logs from the Dynatrace AppSec monitoring to SIEM platforms seems quite an important use-case to me. It isn't supported by Dynatrace, but before putting in a Product Idea, would like to know if eventually someone went the extensions route to be able to get these events to SIEM?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 19:07:41 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/214099#M420</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2023-06-05T19:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using Common Event Format (CEF) with Dynatrace?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215805#M421</link>
      <description>&lt;P&gt;great question and great future RFE &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 13:07:34 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215805#M421</guid>
      <dc:creator>ChadTurner</dc:creator>
      <dc:date>2023-06-22T13:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using Common Event Format (CEF) with Dynatrace?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215855#M422</link>
      <description>&lt;P&gt;I am using FluentD to ingest Syslog and output it in Dynatrace : &lt;A href="https://www.dynatrace.com/support/help/observe-and-explore/logs/log-monitoring/acquire-log-data/send-syslogs-via-fluentd" target="_blank"&gt;https://www.dynatrace.com/support/help/observe-and-explore/logs/log-monitoring/acquire-log-data/send-syslogs-via-fluentd&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Maybe you can use CEF input plugin in the same way:&amp;nbsp;&lt;A href="https://github.com/lunardial/fluent-plugin-parser_cef" target="_blank"&gt;https://github.com/lunardial/fluent-plugin-parser_cef&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 19:23:05 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215855#M422</guid>
      <dc:creator>jegron</dc:creator>
      <dc:date>2023-06-22T19:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using Common Event Format (CEF) with Dynatrace?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215884#M423</link>
      <description>&lt;P&gt;I took a CEF example from &lt;A href="https://support.citrix.com/article/CTX136146/common-event-format-cef-logging-support-in-the-application-firewall" target="_self"&gt;this page&lt;/A&gt;&amp;nbsp;then used &lt;A href="https://agardnerit.github.io/logpusher" target="_self"&gt;logpusher&lt;/A&gt;&amp;nbsp;to send it to Dynatrace via an OpenTelemetry collector. (&lt;A href="https://www.youtube.com/watch?v=BzkzmzPdW5M" target="_self"&gt;see this video for how to use logpusher&lt;/A&gt;).&lt;BR /&gt;&lt;BR /&gt;I then used DQL to filter my incoming log lines:&lt;BR /&gt;&lt;BR /&gt;fetch logs, scanLimitGBytes: 1&lt;BR /&gt;| filter matchesPhrase(content, "act=blocked")&lt;BR /&gt;| sort timestamp desc&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 05:33:11 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215884#M423</guid>
      <dc:creator>adam_gardner</dc:creator>
      <dc:date>2023-06-23T05:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using Common Event Format (CEF) with Dynatrace?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215912#M424</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/167"&gt;@adam_gardner&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It's the other way around: I want to get the Dynatrace AppSec events to a SIEM platform.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 09:11:07 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/215912#M424</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2023-06-23T09:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using Common Event Format (CEF) with Dynatrace?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/216025#M425</link>
      <description>&lt;P&gt;Ahh OK. I misread the initial post. In which case, this seems like a very sensible think to build as an app / workflow.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 00:47:27 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/216025#M425</guid>
      <dc:creator>adam_gardner</dc:creator>
      <dc:date>2023-06-26T00:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using Common Event Format (CEF) with Dynatrace?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/216043#M426</link>
      <description>&lt;P&gt;Yes, this is a good direction for the development of AppSec in DT. I have a similar case at my client and it would be nice to send this information to another tool.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 07:35:15 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/216043#M426</guid>
      <dc:creator>radek_jasinski</dc:creator>
      <dc:date>2023-06-26T07:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone using Common Event Format (CEF) with Dynatrace?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/216052#M427</link>
      <description>&lt;P&gt;Yes, &lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/167"&gt;@adam_gardner&lt;/a&gt; gave a good solution for SaaS environments. In this case, it's a Managed environment though...&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 08:15:51 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/Anyone-using-Common-Event-Format-CEF-with-Dynatrace/m-p/216052#M427</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2023-06-26T08:15:51Z</dc:date>
    </item>
  </channel>
</rss>

