Log Types: NCRATMLog

Overview

NCR Automatic Teller Machines produce XML-based log data, which can be imported into the Snare Central server

Collection

The Snare Epilog agent for Windows agents is capable of collecting and forwarding NCR ATM log data.

Sample Events

<JournalRec><SysTime>10-09-2018 12:54:30.460</SysTime><SeqNum>2996</SeqNum><UID>2996</UID><Content><ItemDepAppSrvItemValidationComplete><NumberOfChequesUSD>4</NumberOfChequesUSD><TotalChequeAmountCAD>CAD 66305.70</TotalChequeAmountCAD><TotalChequeAmountUSD>USD 248.45</TotalChequeAmountUSD><FulfilmentException>None</FulfilmentException><ServiceID>ItemDAS</ServiceID><TotalChequeAmount></TotalChequeAmount><EventID>ItemDAS-ItemValidationComplete</EventID><TransactionReference></TransactionReference><Cheques><Cheque><FrontImageFilename>C:\Program Files\NCR APTRA\RBCSmartATM\TempChequeImages\CHQT5MACK91Gr20181009125350f001.bmp</FrontImageFilename><Codeline>c000045c d########## 100-152-8c</Codeline><XFSIdentifier>1</XFSIdentifier><CourtesyAmountConfidenceLevel>8</CourtesyAmountConfidenceLevel><RearImageFilename>C:\Program Files\NCR APTRA\RBCSmartATM\TempChequeImages\CHQT5MACK91Gr20181009125350r001.bmp</RearImageFilename><RefuseReason>None</RefuseReason><Currency>CAD</Currency><CourtesyAmount>5000</CourtesyAmount><ChequeNumber>1</ChequeNumber><ChequeValidity>Warning</ChequeValidity><ChequeDisputeReference>0</ChequeDisputeReference></Cheque></Cheques><AmountRequestedByMediaGroup><AmountRequestedByMediaGroup><CurrencyID>CAD</CurrencyID><FaceValue>CAD1191150.67</FaceValue><ConvertedValue></ConvertedValue></AmountRequestedByMediaGroup><AmountRequestedByMediaGroup><CurrencyID>USD</CurrencyID><FaceValue>USD252.47</FaceValue><ConvertedValue></ConvertedValue></AmountRequestedByMediaGroup></AmountRequestedByMediaGroup><NumberOfChequesCAD>27</NumberOfChequesCAD><TransactionName></TransactionName><CurrencyType2>USD</CurrencyType2><CurrencyType1>CAD</CurrencyType1></ItemDepAppSrvItemValidationComplete></Content></JournalRec>

Fields

Field

Description

Field

Description

DATE

Event date, in the format YYYY-MM-DD

TIME

Event time, in the format HH:MM:SS

SYSTEM

The source system

TABLE

NCRATMLog

CRITICALITY

 

EVENTID

The type of event generated - eg: ItemDepAppSrvItemValidationComplete

UID

 

SEQNUM

 

STRINGS

The XML content, converted to key=value format, with structure/depth specified using double-colon delimiters, for example: Cheques::Cheque::RefuseReason=InvalidMedia Cheques::Cheque::CourtesyAmount=1000

Notes

-

Â