Hi Nickhill,
In my Splunk environment Kaspersky logs, I was able to extract a few more fields based. However, looking at some of the logs, where viruses are found, I'm not sure what the action should be since there is nothing in the logs indicating what it should be.
The logs that contain "GNRL_EV_VIRUS_FOUND" - the action is currently mapping to unknown with the automatic lookup that is in place. This is happening because we are not able to determine what action should be, i believe this should be mapped to "allowed", but not entirely sure.
I was not able to find any Kaspersky documentation that would help determine this. Are you able to provide any Kaspersky documentation that could help? Also if any documentation regarding the logs for field mapping.
Looking for your reply.
Thanks,
Ramu.R
... View more