- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anyone have a GROK pattern for EMA logs?
Link Copied
4 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Avocado,
Thank you for posting on the Intel® communities.
To move forward with your request we will require the information below:
- What EMA version are you currently using?
- How many endpoints do you have in your deployment?
- Is your installation a multi-server or a single server one?
- How are the endpoints provisioned CCM (client control mode) or ACM (admin control mode)?
- What is the reason you need the GROK pattern for the EMA logs?
- Is this request being done on behalf of a company? If yes, please provide as many details about the company as possible.
Best regards,
Victor G.
Intel Technical Support Technician
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- What EMA version are you currently using? 1.10.1
- How many endpoints do you have in your deployment? Thousands
- Is your installation a multi-server or a single server one? Multi
- How are the endpoints provisioned CCM (client control mode) or ACM (admin control mode)? ACM
- What is the reason you need the GROK pattern for the EMA logs? Because the platform console is immature and requires a tech to log into the server to use the GUI. Even if you copy the logs to a share, they are complex and filled with a lot of information. It becomes very difficult to properly trace an asset configuration without ingesting it into a 3rd party app.
If your logs are ingested into Elastic\LogStash the data can be sliced a multitude of ways. e.g. Filtered for Errors, can follow attempts per asset, see enrollments over time, etc etc.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Avocado,
Thank you for your response.
Please let me review this information internally, and kindly wait for an update.
Once we have more information to share, we will post it on this thread.
Regards,
Victor G.
Intel Technical Support Technician
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Avocado,
Thank you for your patience.
We currently don't provide any documented GROK pattern matching against the EMA logs.
Best regards,
Victor G.
Intel Technical Support Technician
Reply
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page