Reference: Format types

CEF

Common Event Format (CEF) is the default format for HP ArcSight. When you define CEF format for your destination, you can include Advanced Settings such as the device vendor, product and version, product name, version, source, and the end of entry separator character. For the separator, you can use escape characters such as: \t (tab), \n (new line), and \r (carriage return). Select the columns that you want to pass through to the destination.

Default destinations: HP ArcSight

CSV

Comma-separated values. Select whether you want to include column headers in the output. Select the columns that you want to pass through to the destination.

Default destinations: File, ServiceNow

Delimiter separated

To create a delimiter separated format, enter the characters that you want to use for column and row delimiters. In addition to single characters, you can use escape characters such as: \t (tab), \n (new line), and \r (carriage return). Select the columns that you want to pass through to the destination.

Elasticsearch

Valid only when Elasticsearch is selected as the destination. Select the columns that you want to pass through to the destination. For more information, see Creating an Elasticsearch destination.

JSON

JavaScript Object Notation (JSON) is lightweight data-interchange format. You can specify the row delimiter that goes between the individual entries. In addition to single characters, you can use escape characters such as: \t (tab), \n (new line), and \r (carriage return). Select the columns that you want to pass through to the destination.

LEEF

Log Event Extended Format (LEEF) is the default format for: IBM QRadar, LogRhythm, and McAfee SIEM. When you define LEEF format for your destination, you can include Advanced Settings such as the LEEF version, product name, version, source, and the end of entry separator character. In addition to single characters, you can use escape characters such as: \t (tab), \n (new line), and \r (carriage return) for the separator.

Default destinations: IBM QRadar, LogRhythm, and McAfee SIEM

SQL server

When you are exporting data to SQL server, you can map the columns from the source to the columns in the database table. For more information, see Configuring a SQL Server destination.

Syslog

A standard for message logging. You can define the syslog message components, including the facility code, severity, message identifier, version, and separator. For the separator, you can use escape characters such as: \t (tab), \n (new line), and \r (carriage return). Select the columns that you want to pass through to the destination.

Default destinations: Splunk, Socket Receiver

Last updated: 6/19/2018 3:25 PM | Feedback