Log Source Event Mapping
Perform the following steps for Log Source Event Mapping:
- Go to Admin > DSM Editor.
- In Select Log Source Type window, search for Qualys LEEF.
- Click Select.
-
From the Qualys LEEF screen, go to Event Mappings tab.
If you do not see mapping for QualysMultiline, create a new one. -
Click the + icon to add a new mapping.
The Create a new Event Mapping pop-up is displayed.
- Set Event ID as QualysMultiline (without quotes).
- Set Category as QualysMultiline (without quotes).
-
Click Choose Event.
You can see the Event Categorizations pop-up. -
Click Create New.
Set the values as follows:- Name: QualysMultiline Information
- Description: QualysMultiline Information
- Log Source Type: Qualys LEEF
- High-Level Category: System
- Low-LevelCategory: Information
- Severity: 2
-
Click Save.
You are redirected to Event Categorizations. -
Click and select the newly created entry shown in the Search Results table.
-
Click OK.
This takes you back to Create a new Event Mapping window.
-
Click Create.
You are redirected to Qualys LEEF pop-up - Event Mappings tab.
-
Confirm that you now have 3 entries, including Event ID QualysMultiline - Category QualysMultiline.
-
Click Save and close the window.
Enable Last Scan Datetime Parsing
Perform the following steps to enable the last scan date-time parsing:
- Go to Admin > DSM Editor.
- In Select Log Source Type.
- Search and select Qualys LEEF.
- Go to Properties.
- From the Properties, search and open Last Scan Datetime.
- From the Property Configuration > Expression section, click Edit.
- Notice the Enabled field.
This field may be in a disabled state (grayed out). If disabled, select the Enabled field. It changes color. - Click OK in the Expression section.
- Click Save and close the window.
Next Step