We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Hello, The sample parser modules on the SCOT /opt/scot/lib/Scot/Parser/ does not have for ArcSight.
Can i adapt the parser for the splunk.pm. Do i need to make a change on the "parse_message” function" thanks