Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Extracting data from the InterScan Web Security Virtual Appliance (IWSVA) database

    • Updated:
    • 9 Sep 2016
    • Product/Version:
    • InterScan Web Security Virtual Appliance 6.0
    • InterScan Web Security Virtual Appliance 6.5
    • Platform:
    • N/A N/A
Summary

You want to know how to extract the data stored in the IWSVA database to make it available for processing by a third party tool.

Details
Public

IWSVA stores all logs in raw format in the following location:

/etc/iscan/commonlog_data/log_block/0

You can use a script for converting the data into a readable format. It is possible to process this data further but note that Trend Micro does not supply or support any tool for this purpose.

To convert the raw logs, use the following script:

import sys
import zlib
if __name__ == '__main__':
      i = open(sys.argv[1], 'rb')
      data = zlib.decompress(i.read())
      o = open(sys.argv[2], 'wb')
      o.write(data)
      o.close()
      i.close()

To use the script:

  1. Save the script in /root with extension ".py".

    For example: toraw.py

  2. Run it using the following command:

    python /root/<scriptname.py> <raw_log_file_name> <output_file_name.txt>

    For example:

    python /root/toraw.py /etc/iscan/commonlog_data/log_block/0/1445862900_6cbf95f2-7bde-11e5-bc6b-005056011094.log text.txt

To understand the format of the raw logs refer to /usr/trend/commonlog/config/schema/log_block/common_id.py.

Open the file common_id.py with a text editor to understand each entry that maps with the readable raw log.

Premium
Internal
Rating:
Category:
Configure
Solution Id:
1115242
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.


Need More Help?

Create a technical support case if you need further support.