Forum Discussion
Qusai_Ismail
Feb 07, 2023Brass Contributor
Duplicate logs of CEF with Syslog
Hello, Is there a way to remove duplication of CommonSecurity and Syslog when Log collector Server is configured to forward CEF and Syslog. for example F5 WAF firewall sending Syslog with CEF fo...
- Jun 13, 2023i got a solution that worked for me:
i've created a seperate machine used only for CEF logs - on that machine just make an IPTABLES that blocks port 25224.
sudo iptables -A INPUT -p udp --dport 25224 -j DROP
sudo iptables -A OUTPUT -p udp --dport 25224 -j DROP
mikhailf
Steel Contributor
Qusai_Ismail
Feb 08, 2023Brass Contributor
Thanks, but this need to use Azure Monitor agent, not Log Analytic agent, yes?
Bcz we are using Log analytic agent (OMS agent)
Bcz we are using Log analytic agent (OMS agent)
- mikhailfFeb 08, 2023Steel Contributor
I think you can use the data transformation with old Log Analytics agents as well. Because it is done on the Azure level and not on the log forwarder.
Transform or customize data at ingestion time in Microsoft Sentinel (preview) | Microsoft Learn
- Qusai_IsmailFeb 09, 2023Brass ContributorThank you, we find a workaround and solve it by edit oms configuration (/etc/rsyslog.d/security-config-omsagent.conf) to
if $rawmsg contains "CEF:" or $rawmsg contains "ASA-" then {
@@127.0.0.1:25226
stop
}- omrymaMar 16, 2023Copper Contributor
This workaround gets overwritten at some point by the azure sentinel no?