Facing an issue with the ArcSight logger query action

Morning, I'm facing an issue with the ArcSight logger query action where it returns only the _rowid if "fields to fetch" is left blank. Any solution for this?

View files in slack

0 7 311
7 REPLIES 7

@Rahul Balakrishnan Could you please share the query with us so we can understand it better?

@Tom Fridman It's the same for any query. example:
destinationAddress=192.168.56.1

View files in slack

Hi @Rahul Balakrishnan ! Our team confirmed that we have an issue regarding this action. We will fix it as soon as possible. Meanwhile writing you a workaround you can implement. Please delete the line 173 in "ArcSightLoggerManager" Script and than you will get the output as excepted.
You can do that by exporting the integration and importing it.

View files in slack

Thank you

Hi @Rahul Balakrishnan
I wanted to update you that the issue you mentioned here has been fixed in the last version of the integration, and you can try it by updating it in your environment.
Let me know if you have any questions.

Thank you!