<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: custom cisco syslog to cef format in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/390946#M247409</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/113062"&gt;@cadrian90&lt;/a&gt;&amp;nbsp;Welcome to the Cloudera Community!&lt;BR /&gt;&lt;BR /&gt;To help you get the best possible solution, I have tagged our NiFi experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/80381"&gt;@SAMSAL&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp; who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please keep us updated on your post, and we hope you find a satisfactory solution to your query.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jul 2024 18:50:50 GMT</pubDate>
    <dc:creator>DianaTorres</dc:creator>
    <dc:date>2024-07-24T18:50:50Z</dc:date>
    <item>
      <title>custom cisco syslog to cef format</title>
      <link>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/390943#M247406</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have custom syslog Cisco messages in the following format&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;117&amp;gt;2024-07-23T14:09:56Z XXXXXXXXX : %FTD-5-430003: EventPriority: Low, DeviceUUID: xxxxxxxxxxxxx, InstanceID: 2, FirstPacketSecond: 2024-07-23T14:09:56Z, ConnectionID: 32322, AccessControlRuleAction: Allow, SrcIP: A.B.C.D, DstIP: A.B.C.D, SrcPort: 42308, DstPort: 24224, Protocol: tcp, IngressInterface: XXX, EgressInterface: XXX, IngressZone: XXX, EgressZone: YYY, IngressVRF: Global, EgressVRF: Global, ACPolicy: AAA-BBB,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to use NIFI to format to CEF ( common event format ). Any help which processors to use, please?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 18:27:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/390943#M247406</guid>
      <dc:creator>cadrian90</dc:creator>
      <dc:date>2024-07-24T18:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: custom cisco syslog to cef format</title>
      <link>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/390946#M247409</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/113062"&gt;@cadrian90&lt;/a&gt;&amp;nbsp;Welcome to the Cloudera Community!&lt;BR /&gt;&lt;BR /&gt;To help you get the best possible solution, I have tagged our NiFi experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/80381"&gt;@SAMSAL&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/35454"&gt;@MattWho&lt;/a&gt;&amp;nbsp; who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please keep us updated on your post, and we hope you find a satisfactory solution to your query.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 18:50:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/390946#M247409</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2024-07-24T18:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: custom cisco syslog to cef format</title>
      <link>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/390979#M247418</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/113062"&gt;@cadrian90&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Im not aware of direct way to do that in Nifi. I know there are services\processor like CEFFeader and ParseCEF used to consume CEF format but not to write as CEF. the good news is that you can write your custom code to create service or new processor&amp;nbsp; to do that using Either Python or Java if you happen to know a way of doing using code.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 17:26:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/390979#M247418</guid>
      <dc:creator>SAMSAL</dc:creator>
      <dc:date>2024-07-25T17:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: custom cisco syslog to cef format</title>
      <link>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/391014#M247437</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/113062"&gt;@cadrian90&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I agree with &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/80381"&gt;@SAMSAL&lt;/a&gt;&amp;nbsp;response.&amp;nbsp; Typically the &lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M4/components/org.apache.nifi/nifi-standard-nar/2.0.0-M4/org.apache.nifi.processors.standard.ConvertRecord/index.html" target="_blank"&gt;ConvertRecord&lt;/A&gt; processor is what would be used here.&amp;nbsp; The processor support numerous record readers and numerous record writers.&amp;nbsp; The &lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M4/components/org.apache.nifi/nifi-record-serialization-services-nar/2.0.0-M4/org.apache.nifi.grok.GrokReader/index.html" target="_blank"&gt;GrokReader&lt;/A&gt; is what would be commonly used to parse unstructured data like your Cisco syslog messages.&amp;nbsp; While the GrokReader has bulit in pattern file, you may fond yourself needing to define a custom pattern file for your specific data.&amp;nbsp; You might find this other community post helpful here:&lt;BR /&gt;&lt;A href="https://community.cloudera.com/t5/Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/td-p/233095" target="_blank"&gt;https://community.cloudera.com/t5/Support-Questions/ExtractGrok-processor-Writing-Regex-to-parse-Cisco-syslog/td-p/233095&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Beyond above, this is where it becomes challenging since Apache NiFi only has a CEFReader and no CEFRecordSetWriter (perhaps you can raise an Apache Jira asking for this new reader and someone in the Apache community may be able to help)&lt;BR /&gt;&lt;BR /&gt;There does exist a &lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M4/components/org.apache.nifi/nifi-scripting-nar/2.0.0-M4/org.apache.nifi.record.script.ScriptedRecordSetWriter/index.html" target="_blank"&gt;ScriptedRecordSetWriter&lt;/A&gt; that if you know how to scripted out the CEF format, maybe you can use that.&amp;nbsp; I really would not be able to help there myself.&lt;BR /&gt;Maybe you can look into the &lt;A href="https://nifi.apache.org/documentation/nifi-2.0.0-M4/components/org.apache.nifi/nifi-record-serialization-services-nar/2.0.0-M4/org.apache.nifi.csv.CSVRecordSetWriter/index.html" target="_blank"&gt;CSVRecordSetWriter&lt;/A&gt; to see if selecting a custom format would facilitate an output like CEF.&amp;nbsp; Again not something I have tried myself.&lt;BR /&gt;&lt;BR /&gt;Hope this helps you with your use case journey.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please help our community thrive. If you found&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;any&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;of the suggestions/solutions provided helped you with solving your issue or answering your question, please take a moment to login and click "&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Accept as Solution&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;" on&amp;nbsp;&lt;STRONG&gt;one or more&lt;/STRONG&gt;&amp;nbsp;of them that helped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;BR /&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 13:17:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/391014#M247437</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2024-07-26T13:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: custom cisco syslog to cef format</title>
      <link>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/391129#M247486</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/113062"&gt;@cadrian90&lt;/a&gt;&amp;nbsp;Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 02:01:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/custom-cisco-syslog-to-cef-format/m-p/391129#M247486</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2024-07-30T02:01:13Z</dc:date>
    </item>
  </channel>
</rss>

