Parse the known_*.log and software.log into SO #10265
Replies: 1 comment
-
Zeek software.log should work in the new Security Onion 2.4: known_*.log would require additional manual configuration. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
So far, the known_*.log and software.log files (https://docs.zeek.org/en/master/logs/known-and-software.html) are generated by default by Zeek but not parsed by Kibana / SO while this info is useful. Once these are parsed, please also add default OQL queries to view them in the Hunt.
Beta Was this translation helpful? Give feedback.
All reactions