Log Types: NCRATMLog
Overview
NCR Automatic Teller Machines produce XML-based log data, which can be imported into the Snare Central server
Collection
The Snare Epilog agent for Windows agents is capable of collecting and forwarding NCR ATM log data.
Sample Events
<JournalRec><SysTime>10-09-2018 12:54:30.460</SysTime><SeqNum>2996</SeqNum><UID>2996</UID><Content><ItemDepAppSrvItemValidationComplete><NumberOfChequesUSD>4</NumberOfChequesUSD><TotalChequeAmountCAD>CAD 66305.70</TotalChequeAmountCAD><TotalChequeAmountUSD>USD 248.45</TotalChequeAmountUSD><FulfilmentException>None</FulfilmentException><ServiceID>ItemDAS</ServiceID><TotalChequeAmount></TotalChequeAmount><EventID>ItemDAS-ItemValidationComplete</EventID><TransactionReference></TransactionReference><Cheques><Cheque><FrontImageFilename>C:\Program Files\NCR APTRA\RBCSmartATM\TempChequeImages\CHQT5MACK91Gr20181009125350f001.bmp</FrontImageFilename><Codeline>c000045c d########## 100-152-8c</Codeline><XFSIdentifier>1</XFSIdentifier><CourtesyAmountConfidenceLevel>8</CourtesyAmountConfidenceLevel><RearImageFilename>C:\Program Files\NCR APTRA\RBCSmartATM\TempChequeImages\CHQT5MACK91Gr20181009125350r001.bmp</RearImageFilename><RefuseReason>None</RefuseReason><Currency>CAD</Currency><CourtesyAmount>5000</CourtesyAmount><ChequeNumber>1</ChequeNumber><ChequeValidity>Warning</ChequeValidity><ChequeDisputeReference>0</ChequeDisputeReference></Cheque></Cheques><AmountRequestedByMediaGroup><AmountRequestedByMediaGroup><CurrencyID>CAD</CurrencyID><FaceValue>CAD1191150.67</FaceValue><ConvertedValue></ConvertedValue></AmountRequestedByMediaGroup><AmountRequestedByMediaGroup><CurrencyID>USD</CurrencyID><FaceValue>USD252.47</FaceValue><ConvertedValue></ConvertedValue></AmountRequestedByMediaGroup></AmountRequestedByMediaGroup><NumberOfChequesCAD>27</NumberOfChequesCAD><TransactionName></TransactionName><CurrencyType2>USD</CurrencyType2><CurrencyType1>CAD</CurrencyType1></ItemDepAppSrvItemValidationComplete></Content></JournalRec>
Fields
Field | Description |
---|---|
DATE | Event date, in the format YYYY-MM-DD |
TIME | Event time, in the format HH:MM:SS |
SYSTEM | The source system |
TABLE | NCRATMLog |
CRITICALITY | Â |
EVENTID | The type of event generated - eg: ItemDepAppSrvItemValidationComplete |
UID | Â |
SEQNUM | Â |
STRINGS | The XML content, converted to key=value format, with structure/depth specified using double-colon delimiters, for example: Cheques::Cheque::RefuseReason=InvalidMedia Cheques::Cheque::CourtesyAmount=1000 |
Notes
-
Â