We have a custom log source type for our app, so from the dsm editor I'm trying to add MessageID as a custom property. Now, I have written a regex and extraction works fine as I see in Log Activity Preview. But when I try to save in the DSM editor I get the following error. Even no other property is getting saved for that particular Log Source Type.
If change my Log Source Type(Some other custom built log source type dsmeditor) and add the same property in it and it saves successfully.
Tried the same thing in a fresh installed Qradar. Still, the same problem exists. Any way to debug this?
Answer by MitchellMacLean (26) | Jun 29, 2018 at 09:12 AM
This is an issue that is likely going to require a support ticket. We would suggest that you open a case and collect logs for QRadar. We can try to assist via the forum, but this issue is likely going to be too complicated to diagnose here.
What to do
- Collect logs from the Console. - Log in to https://ibm.biz/qradarsupport
You can answer the following (make sure you also include this in your case)
1- What version of Qradar are you using?
2- What type of property is MessageID? (Text, Number, Alphanumeric, etc)
3- What regex and capture group are you using for that property in the DSM editor?
The information from items 1 to 3 will help us understand this issue a little better.
Invalid Extension Document : null 6 Answers
Hardcoded devicetypeid doesn't work with other application with same devicetypeid? 0 Answers
Incorrect event name and extractions as Event 0 2 Answers
Proofpoint TAP parsing assistance 2 Answers
How the source/destination ip are determined in log activity? 1 Answer