Rhebo
ArchivedThe Rhebo application normalizes Rhebo events. You can further customize the searches to perform in-depth analysis.
Release Details
Package Details
- Compiled Normalizer
- RheboCEFCompiledNormalizer
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the Rhebo v5.0.1 application:
- Download the Rhebo package from the Download section above.
- Add Rhebo as the required device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
Past Release
For LogPoint v6.0.0 to v6.6.6 ▾
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Log Format
Expected Log Format
CEF
Log Sample
Jan 13 07:29:19 OD-VM-1-5 CEF: 0|Rhebo|Controller|1.5|alert|MAC/FUNCTION|2|deviceMacAddress=xx:xx:xx:xx:xx:xxcs1=PROFINET_RT_CLASS_2_UNICAST cs2=78d3fb78d0f0baa5 rt=11111111111111111 smac=xx:xx:xx:xx:xx:xx dmac=xx:xx:xx:xx:xx:xx app=PROFINET
To export data to LogPoint, use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.