Hello everyone,
I hope someone can help me with a little issue I am having with parsing a CSV log and outputting to a syslog server.
I have created a custom script that runs on a admin server and collects the MS AppLocker logs from remote workstations and puts all the output to a CSV file. I want Log Parser 2.2 to pars the CSV file and write all the messages to a syslog server in our environment.
I am using this query:
logparser.exe -i:CSV -headerRow:on "SELECT Timestamp,Computer as MyHostname,Level,EventID as Tag,PolicyName,FilePath as Message INTO @syslogserver.mydomain.com:514 FROM Logs\Log.csv" -o:SYSLOG -severity:INFO -facility:local6 -hostName:$MyHostname -processName:AppLocker
But I get his error: Error: Invalid value "" for parameter "hostName"
Log Parser is not able to use the $MyHostname field in the -hostName option, if I specify the hostname manually, then the query works fine.
My CSV file looks like this:
EventID,Level,Computer,Timestamp,RuleName,PolicyName,FilePath,FileHash
8004,Warning,WORKSTATION01,2016-07-08T09:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION01,2016-07-08T10:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION01,2016-07-08T11:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION02,2016-07-08T12:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION02,2016-07-08T13:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION02,2016-07-08T14:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION03,2016-07-08T15:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION03,2016-07-08T16:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION03,2016-07-08T17:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION04,2016-07-08T18:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION04,2016-07-08T19:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
8004,Warning,WORKSTATION04,2016-07-08T19:13:00,-,EXE,%OSDRIVE%\USERS\USERNAME\APPDATA\LOCAL\GOOGLE\UPDATE\GOOGLEUPDATE.EXE,81356CA6AA72790C18B848627EB0749AE611A86BD9F2973B6A9AEAB9893F291F
Thoughts? Any help would be much appreciated! ;-)