Detected Bias Types
Windows First
🔧
Windows Tools
Windows Heavy
Summary
The documentation lists ASIM parsers for a wide variety of sources, but Windows-centric sources (e.g., Windows Events, Sysmon for Windows, Microsoft Defender XDR, Windows Security Events, IIS) are consistently present and often described in detail. Windows event types and connectors are frequently mentioned, sometimes with specific event IDs and collection agents. Linux sources are present (e.g., Sysmon for Linux, sshd, su, sudo, authpriv, Apache HTTP Server), but Windows examples and tools appear more frequently and are often listed before Linux equivalents in each section.
Recommendations
- Ensure Linux and macOS sources are given equal prominence in each parser category, listing them alongside or before Windows sources where appropriate.
- Expand notes for Linux/macOS sources to match the detail given for Windows (e.g., specify event types, collection methods, and supported connectors).
- Add examples or references for Linux/macOS collection agents and connectors (e.g., mention NXlog for Linux, syslog collection details, or other open-source agents).
- Where Windows event IDs and collection methods are described, provide equivalent details for Linux/macOS (e.g., syslog facility, event types, log file locations).
- Consider including macOS-specific sources if supported, or clarify platform support for each parser.