<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Standard Logging Format &#8211; Common Event Expression (CEE)</title>
	<atom:link href="http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/feed/" rel="self" type="application/rss+xml" />
	<link>http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/</link>
	<description>Big data analytics and visualization</description>
	<lastBuildDate>Tue, 15 May 2012 02:36:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Raffael Marty</title>
		<link>http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/comment-page-1/#comment-9904</link>
		<dc:creator>Raffael Marty</dc:creator>
		<pubDate>Tue, 27 Nov 2007 18:08:44 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/#comment-9904</guid>
		<description>It is really close now! Hang on tight. The site is ready, but is going through approval processes. It&#039;s very very close!</description>
		<content:encoded><![CDATA[<p>It is really close now! Hang on tight. The site is ready, but is going through approval processes. It&#8217;s very very close!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sectrix</title>
		<link>http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/comment-page-1/#comment-9903</link>
		<dc:creator>sectrix</dc:creator>
		<pubDate>Tue, 27 Nov 2007 17:54:26 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/#comment-9903</guid>
		<description>On http://cee.mitre.org is only apache test page! Where I can get CEE?</description>
		<content:encoded><![CDATA[<p>On <a href="http://cee.mitre.org" rel="nofollow">http://cee.mitre.org</a> is only apache test page! Where I can get CEE?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raffy&#8217;s Computer Security Blog &#187; CEE - CEF - Event Interoperability Standards</title>
		<link>http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/comment-page-1/#comment-6688</link>
		<dc:creator>Raffy&#8217;s Computer Security Blog &#187; CEE - CEF - Event Interoperability Standards</dc:creator>
		<pubDate>Wed, 18 Jul 2007 22:44:48 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/#comment-6688</guid>
		<description>[...] for example is something that should not depend on the syntax and vice versa. I keep haing to make that point. The ArcSight CEF standard is not bound to any transport. Use anything. If you don&#8217;t have [...]</description>
		<content:encoded><![CDATA[<p>[...] for example is something that should not depend on the syntax and vice versa. I keep haing to make that point. The ArcSight CEF standard is not bound to any transport. Use anything. If you don&#8217;t have [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DC</title>
		<link>http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/comment-page-1/#comment-6298</link>
		<dc:creator>DC</dc:creator>
		<pubDate>Fri, 29 Jun 2007 14:01:26 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/#comment-6298</guid>
		<description>In this post, you state there are 20 vendors or so working with CEF.  Are they posted somewhere on who they are?  

http://www.loganalysis.org/pipermail/loganalysis/2007-April/000089.html</description>
		<content:encoded><![CDATA[<p>In this post, you state there are 20 vendors or so working with CEF.  Are they posted somewhere on who they are?  </p>
<p><a href="http://www.loganalysis.org/pipermail/loganalysis/2007-April/000089.html" rel="nofollow">http://www.loganalysis.org/pipermail/loganalysis/2007-April/000089.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Corlette</title>
		<link>http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/comment-page-1/#comment-4620</link>
		<dc:creator>David Corlette</dc:creator>
		<pubDate>Wed, 16 May 2007 14:55:39 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2007/04/19/standard-logging-format-common-event-exchange-cee/#comment-4620</guid>
		<description>Hello,

Item 2 above is entirely not true; there is an existing standard called XDAS which defines event taxonomy as well as formats (item 1). This is an open standard developed by the OpenGroup.

&lt;a href=&quot;http://www.opengroup.org/security/das/xdas_int.htm&quot; rel=&quot;nofollow&quot;&gt;http://www.opengroup.org/security/das/xdas_int.htm
&lt;/a&gt;

It also includes an API definition for auditing that can use a variety of transport methods; item 3 above is not necessary as the format should be independent of delivery method.</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>Item 2 above is entirely not true; there is an existing standard called XDAS which defines event taxonomy as well as formats (item 1). This is an open standard developed by the OpenGroup.</p>
<p><a href="http://www.opengroup.org/security/das/xdas_int.htm" rel="nofollow"></a><a href="http://www.opengroup.org/security/das/xdas_int.htm" rel="nofollow">http://www.opengroup.org/security/das/xdas_int.htm</a></p>
<p>It also includes an API definition for auditing that can use a variety of transport methods; item 3 above is not necessary as the format should be independent of delivery method.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

