Netflow Playbook #10444
Netflow Playbook
#10444
Replies: 1 comment 3 replies
-
Have you checked out the documentation on sofilter? - https://docs.securityonion.net/en/2.3/playbook.html?highlight=sofilter#tuning-plays |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I'm running 2.3.250. I'm new to SO, and have been watching videos and reading like crazy. I have a few of my sites sending Netflow data in and it comes up just fine on the dashboard and I can drill down with hunt. My goal is to start using alerts to look for Netflow based IOCs. I've tried a million sigma entries and can't seem to get a Netflow based alert to populate. Can anyone point to existing documentation of it in a working environment? I saw someone reference using a custom sofilter statement, but I wasn't able to find the example or syntax. Thank you in advance for any suggestions!
Beta Was this translation helpful? Give feedback.
All reactions