Reading Gravity Zone Syslog
I am writing a Python program to read Gravity Zone syslogs and wondering about the log structure. I understand that Gravity Zone can produce different events (Malware detection events, phishing/fraud events, etc.)
I am trying to understand if those events have some sort of header that identifies the event type or are these events placed into different logs?
For example, here is a log snippet (from the Gravity Zone manual), but other than read the raw JSON, how does someone know that this is a malware event? Is there a header? Is there a "type_of_event" field somewhere? Reading the raw JSCON to see if the word "malware" appears as a field seems sub-optimal, so just wondering if I am missing something?
Here is the sample JSON - yes I can kind of figure out that the this is a malware event due to the malware_type field, but I would rather say "If event_type = 'malware_event' - but I don't see anywhere in the syslog samples where that is possible.
If anyone has a tool they are using to read these logs, would love to hear your approach...thank you in advance.
Mar 15 23:04:56 gz gravityzone: [av] {"computer_name":"DEMO-W7-11","computer_ip" :"192.168.5.137","computer_id":"532806300678598e738b4571","product_installed":"E PS","malware_type":"file","malware_name":"BAT.Trojan.FormatC.Z","file_path":"C:\ \Users\\username\\Desktop\\New Text Document.txt","final_status":"quarantined"," timestamp":"2015-03-15T21:04:49.000Z","module":"av"}
Answers
-
Hi Member,
Support for business product on forum is very limited. Kindly drop an email to bitdefender support at [email protected] regarding your query .They will reply back asap.
Regards
Flex
(Bitdefender beta tester 2019/ 2020)
OMEN Laptop 15-en1037AX (Bitdefender Total Security) & Samsung Galaxy S22 Ultra (Bitdefender Mobile Security)
0 -
Kindly refrain from posting spam comments or your account will be ban. In extreme cases your IP will be blocked from creating new accounts on bitdefender forum. This place is not for promoting your website.
Regards
Flex
(Bitdefender beta tester 2019/ 2020)
OMEN Laptop 15-en1037AX (Bitdefender Total Security) & Samsung Galaxy S22 Ultra (Bitdefender Mobile Security)
1 -
Kindly refrain from posting spam comments or your account will be ban. In extreme cases your IP will be blocked from creating new accounts on bitdefender forum. This place is not for promoting your website.
Regards
Flex
(Bitdefender beta tester 2019/ 2020)
OMEN Laptop 15-en1037AX (Bitdefender Total Security) & Samsung Galaxy S22 Ultra (Bitdefender Mobile Security)
1 -
Kindly stop promoting your website. This place is to help bitdefender customer and not for promoting your websites.
@Mike_BD kindly check on these comments
Regards
Flex
(Bitdefender beta tester 2019/ 2020)
OMEN Laptop 15-en1037AX (Bitdefender Total Security) & Samsung Galaxy S22 Ultra (Bitdefender Mobile Security)
1 -
OMEN Laptop 15-en1037AX (Bitdefender Total Security) & Samsung Galaxy S22 Ultra (Bitdefender Mobile Security)
1 -
OMEN Laptop 15-en1037AX (Bitdefender Total Security) & Samsung Galaxy S22 Ultra (Bitdefender Mobile Security)
1
All Time Leaders
Categories
- 1.6K All Categories
- 653 Windows
- 76 Mac
- 289 Mobile Security
- 174 VPN
- 243 Central & Subscriptions
- 274 Other Products & Services
- 62 Security Research Team
- 111 Product features and Ideation
- 96 Enterprise Security
- 501 General Topics
- 112 News & Blogs
- 4.8K Home & home office protection
- 24.2K Old forum topics