Skip to main content

Log StreamLog Stream Guide

Table of Contents

Customize a Default Parser

When you build a custom parser, based on a default Exabeam parser as a template, your custom parser will not update automatically when the default parser is refreshed by Exabeam.

You can customize a default parser, to add new field mapping or event builder rules, without creating a custom parser. This requires no additional effort to maintain the customizations, as they will automatically be updated when Exabeam refreshes their default parsers.

To customize a default parser:

  1. On the Parsers Overview tab of the Log Stream home page, click the (PM-ThreeDotMenu.jpg) menu on the default parser you wish to customize, and select Customize.

  2. Add sample log lines, change the parser conditions, activity type, time format, associated vendor and product, field mapping, and event builder rules. Click Next at each step, until you reach the last step.

    Note

    See Create a Custom Parser for detailed information about each step.

  3. Click Finish.