Adding Parser Overrides

A parser override is a file provided by ArcSight used to resolve an issue with the parser for a specific connector, or to support a newer version of a supported device where the log file format changed slightly or new event types were added.

To use parser overrides, you need to:

Follow the steps below.

To upload a parser override file:

  1. Click Administration > Repositories.

  2. Click Parser Overrides under the Repositories section in the management panel.

  3. On the Parser Overrides tab, click the Upload To Repository button.

  4. Follow the wizard to upload the file. When prompted by the wizard, make sure you:

    • Select the Individual Files option from the Select the type of file that you want to upload field.

    • Add a slash (/) after fcp before adding the folder name in the Enter the sub folder where the files will be uploaded field. For example, fcp/multisqlserverauditdb.

      Note: The folder name may only contain letters and numbers. Do not include special characters such as (, ), <, or >.

      When the upload is complete, the parser override file is listed in the table on the Parser Overrides tab.

To download the parser override file to a container:

  1. Click Administration > Repositories.

  2. Click Parser Overrides under the Repositories section in the management panel.

  3. In the table on the Parser Overrides tab, locate the parser override file you want to download and click the up arrow next to the file.

  4. Follow the wizard to select the container to which you want to add the parser overrides.

    When the wizard completes, the parser overrides are deployed in the selected container.

    Note: You can download a parser override file from ArcSight Marketplace. For more information, refer to Sharing Connectors in ArcSight Marketplace.

To verify that the parser override has been applied successfully, issue a Get Status command to the connector. See Sending a Command to a Connector. In the report that appears, check for the line starting with ContentInputStreamOverrides.