Adding Parser Overrides
A parser override is a file provided by ArcSight used to resolve an issue with the parser for a specific connector, or to support a newer version of a supported device where the log file format changed slightly or new event types were added.
To use parser overrides, you need to:
-
Upload a parser override file to the Parser Overrides repository.
-
Download the parser override file to the container that contains the connector that will use the parser override.
Follow the steps below.
To upload a parser override file:
-
Click Administration > Repositories.
-
Click Parser Overrides under the Repositories section in the management panel.
-
On the Parser Overrides tab, click the Upload To Repository button.
-
Follow the wizard to upload the file. When prompted by the wizard, make sure you:
-
Select the Individual Files option from the Select the type of file that you want to upload field.
-
Add a slash (/) after fcp before adding the folder name in the Enter the sub folder where the files will be uploaded field. For example,
fcp/multisqlserverauditdb
.Note: The folder name may only contain letters and numbers. Do not include special characters such as (, ), <, or >.
When the upload is complete, the parser override file is listed in the table on the Parser Overrides tab.
To download the parser override file to a container:
-
Click Administration > Repositories.
-
Click Parser Overrides under the Repositories section in the management panel.
-
In the table on the Parser Overrides tab, locate the parser override file you want to download and click the up arrow next to the file.
-
Follow the wizard to select the container to which you want to add the parser overrides.
When the wizard completes, the parser overrides are deployed in the selected container.
Note: You can download a parser override file from ArcSight Marketplace. For more information, refer to Sharing Connectors in ArcSight Marketplace.
To verify that the parser override has been applied successfully, issue a Get Status command to the connector. See Sending a Command to a Connector. In the report that appears, check for the line starting with ContentInputStreamOverrides
.