Each data type is tagged with a ModuleType to enable Logpoint’s normalization:
Data Source |
ModuleType Value |
Purpose |
|---|---|---|
Windows Event Logs |
|
Triggers Logpoint event log normalization |
DHCP Logs |
N/A (CSV parsed) |
Parsed as structured CSV data |
DNS Debug Logs |
N/A (raw format) |
Sent as raw event data |
Registry Monitoring |
|
Required for regmon parser |
ModuleType="event_log"
ModuleType="event_log" EventID=4624
ModuleType="registry_scanner"
Converted to JSON format
Wrapped in Syslog BSD format
Sent over UDP port 514
Parsed as CSV
Converted to structured format
Forwarded via Syslog
Sent as raw event data
Wrapped in Syslog format
Native im_regmon format
Directly compatible with Logpoint’s parser
NOT converted to JSON
We are glad this guide helped.
Please don't include any personal information in your comment
Contact Support