Quantcast
Channel: General Discussion
Viewing all articles
Browse latest Browse all 204

Issues Log Parser sending to Syslog server

$
0
0

Hello everyone,

I hope someone can help me with a little issue I am having with parsing a CSV log and outputting to a syslog server.

I have created a custom script that runs on a admin server and collects the MS AppLocker logs from remote workstations and puts all the output to a CSV file. I want Log Parser 2.2 to pars the CSV file and write all the messages to a syslog server in our environment.

I am using this query:

logparser.exe -i:CSV -headerRow:on "SELECT Timestamp,Computer as MyHostname,Level,EventID as Tag,PolicyName,FilePath as Message INTO @syslogserver.mydomain.com:514 FROM Logs\Log.csv" -o:SYSLOG -severity:INFO -facility:local6 -hostName:$MyHostname -processName:AppLocker

But I get his error: Error: Invalid value "" for parameter "hostName"

Log Parser is not able to use the $MyHostname field in the -hostName option, if I specify the hostname manually, then the query works fine.

My CSV file looks like this:

EventID,Level,Computer,Timestamp,RuleName,PolicyName,FilePath,FileHash
8004,Warning,WORKSTATION01,2016-07-08T09:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION01,2016-07-08T10:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION01,2016-07-08T11:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION02,2016-07-08T12:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION02,2016-07-08T13:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION02,2016-07-08T14:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION03,2016-07-08T15:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION03,2016-07-08T16:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION03,2016-07-08T17:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION04,2016-07-08T18:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION04,2016-07-08T19:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION04,2016-07-08T19:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F

Thoughts? Any help would be much appreciated! ;-)


Viewing all articles
Browse latest Browse all 204

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>