Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

BitDefender

Archived
BitDefender normalizes BitDefender events. You can further customize the searches to perform in-depth analysis.

Release Details

Version: 5.1.0
Release date: April 26, 2024
Supported On: Logpoint v7.4.0 or later for log source template
SHA 256: a961ae317b4dada8b2ef4de6cf5845746f5a98d4362590564c6651211f8a49b1
Download

Package Details

  1. Normalization Package
    • LP_BitDefender
  2. Compiled Normalizer
    • BitDefenderCompiledNormalizer

Enhancement

KB-23288
Added Syslog Collector based BitDefender log source template, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .

Installation

To install BitDefender :

  1. Download the .pak file from the Download link above.
  2. Go to Settings >> System Settings from the navigation bar and click Applications .
  3. Click Import .
  4. Browse to the downloaded .pak file.
  5. Click Upload .

Past Releases

BitDefender v5.0.1 ▾
Version: 5.0.1
Release date: 2020-05-14
Supported On: LogPoint v6.7.0 and later
SHA 256: ec38ca60ed4dfc5bf8481fcca7001c5244ba66b17ab55786c251abf7ab0638dd
Download

Enhancement

A minor update has been done in the application’s normalizer for better signature handling.
BitDefender v3.3.0 ▾
Version: 3.3.0
Release date: 2020-05-14
Supported On: LogPoint v6.0.0 to v6.6.6
SHA 256: 35cf8d93da98b1217b69c25a3099007e276c940537649536c9888e35932316fb
Download

Enhancement

A minor update has been done in the application’s normalizer for better signature handling.

Log Format

Expected Log Format

Semi-colon separated

Log Samples

<14>Jun 9 08:38:46 CPHBITxxxxx gravityzone: [modules] {"computer_name":"XXXXXXXXXXXXX", "computer_ip":"1.1.1.1", "computer_id":"XXXXXXXXXXXXXXXXXXXXXXXXXXXXX", "product_installed":"EPS", "malware_status":1, "avc_status":0, "ids_status":0, "module":"modules"}

gravityzone: [av] {"computer_name":"server", "computer_fqdn":"server.abc.com", "computer_ip":"1.1.1.0", "computer_id":"xyzfsjf", "product_installed":"BEST", "user":{"id":"x-x-x-5", "name":"xyz@abc.com"}, "malware_type":"file", "malware_name":"Trojan", "file_path":"C:\\Downloads.lnk", "final_status":"deleted", "timestamp":"2017-04-11T03:31:42.000Z", "module":"av"}

<14>Mar 1 09:19:14 bitdef02 gravityzone: [av] {"computer_name":"SERVER01", "computer_fqdn":"SERVER01.DOMAIN.DK", "computer_ip":"10.10.20.20", "computer_id":"57xxxxxxxxxxxxxxxxxxxxxxxxxxxx", "product_installed":"BEST", "user": {"id":"S-1-5-21-456xxxxxx-456xxxxxxx-7567xxxxxxx-12xxxxxx", "name":"USER@DOMAIN.DK"}, "malware_type":"file", "malware_name":"Trojan.xxx.xxxx", "file_path":"D:Downloads.lnk", "final_status":"deleted", "timestamp":"2017-03-01T09:19:12.000Z", "module":"av"}

<14>Jun 8 12:04:09 CPHBITDEF01 gravityzone: [av] {"computer_name":"XXXXXXXXXXXXXX", "computer_ip":"1.1.1.1", "computer_id":"xxxxxxxxxxxxxxxxxxxx", "product_installed":"EPS", "malware_type":"file", "malware_name":"Gen:xxxxx.xxx.1014xxxx", "file_path":"E:\\OKxxxx Oxxxxxxx Mugaxxxx.exe", "final_status":"blocked", "timestamp":"2015-06-08T12:04:03.000Z", "module":"av"}

<14>Nov 4 14:43:02 i01234 logpoint: message repeated 5 times: [lp] {"module":"lp", "product_installed":"BEST", "user": {"id":null,"name":null}, "VM_NAME":"logpoint", "VM_ID":"vm-4575", "UUID_INSTANCE":"XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX", "UUID_BIOS":"XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXXX", "computer_name":"logpoint", "computer_fqdn":"logpoint.com", "computer_ip":"XXX.XXX.XXX.XX", "computer_id":"XXXXXXXXXXXXXXXXXXX", "malware_type":"file", "malware_name":"Test-File (not a virus)", "hash":"275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f", "final_status":"deleted", "file_path":"D:\Cisco.txt", "timestamp":"2019-11-04T14:42:48.000Z"}]

To export data to Logpoint, use Syslog collector on port 514 on the Logpoint server.

Support

If you have any questions or require assistance, create a support ticket.

Comments

Article is closed for comments.

Follow

Related articles

  • Blue Coat
  • Universal REST API Fetcher
  • Microsoft Defender ATP
  • BIG-IP
  • Crowdstrike
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.