The Qualys documentation for the TA states that there may be a problem with parsing the RESULTS field because some values are multi-line values. Since this is the only field that may contain a multi-line value, what would be the best way to parse the data?
From props.conf:
[qualys:hostDetection]
DATETIME_CONFIG =
NO_BINARY_CHECK = true
SHOULD_LINEMERGE = true
category = Custom
disabled = false
KV_MODE = auto
KV_MODE = auto parses all the fields correctly, except when the RESULTS field has a multi-line value.
Thanks in advance!
Adding BREAK_ONLY_BEFORE = (HOSTVULN:|HOSTSUMMARY:) to props.conf resolved my issue.
Adding BREAK_ONLY_BEFORE = (HOSTVULN:|HOSTSUMMARY:) to props.conf resolved my issue.
Hi @jamesco ,
Hope you are doing well!
We are also trying to parse RESULTS field from Qualys TA, but event parsing having issue. I have updated props.conf as above. Could please help me on this? Did you updated any python script to parse events properly.
Thanks in advance.