- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Anyone have a GROK pattern for EMA logs?
Lien copié
4 Réponses
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hello Avocado,
Thank you for posting on the Intel® communities.
To move forward with your request we will require the information below:
- What EMA version are you currently using?
- How many endpoints do you have in your deployment?
- Is your installation a multi-server or a single server one?
- How are the endpoints provisioned CCM (client control mode) or ACM (admin control mode)?
- What is the reason you need the GROK pattern for the EMA logs?
- Is this request being done on behalf of a company? If yes, please provide as many details about the company as possible.
Best regards,
Victor G.
Intel Technical Support Technician
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
- What EMA version are you currently using? 1.10.1
- How many endpoints do you have in your deployment? Thousands
- Is your installation a multi-server or a single server one? Multi
- How are the endpoints provisioned CCM (client control mode) or ACM (admin control mode)? ACM
- What is the reason you need the GROK pattern for the EMA logs? Because the platform console is immature and requires a tech to log into the server to use the GUI. Even if you copy the logs to a share, they are complex and filled with a lot of information. It becomes very difficult to properly trace an asset configuration without ingesting it into a 3rd party app.
If your logs are ingested into Elastic\LogStash the data can be sliced a multitude of ways. e.g. Filtered for Errors, can follow attempts per asset, see enrollments over time, etc etc.
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hello Avocado,
Thank you for your response.
Please let me review this information internally, and kindly wait for an update.
Once we have more information to share, we will post it on this thread.
Regards,
Victor G.
Intel Technical Support Technician
- Marquer comme nouveau
- Marquer
- S'abonner
- Sourdine
- S'abonner au fil RSS
- Surligner
- Imprimer
- Signaler un contenu inapproprié
Hello Avocado,
Thank you for your patience.
We currently don't provide any documented GROK pattern matching against the EMA logs.
Best regards,
Victor G.
Intel Technical Support Technician

Répondre
Options du sujet
- S'abonner au fil RSS
- Marquer le sujet comme nouveau
- Marquer le sujet comme lu
- Placer ce Sujet en tête de liste pour l'utilisateur actuel
- Marquer
- S'abonner
- Page imprimable