Data Lake #12556
Data Lake
#12556
Replies: 1 comment 4 replies
-
When you pull logs directly from the service using the Elastic Agent logs are automatically parsed, checkout the supported integrations here https://docs.securityonion.net/en/2.4/elastic-fleet.html#integrations However, if pulling from a data lake you would need some custom ingest pipelines to parse the data for you correctly |
Beta Was this translation helpful? Give feedback.
4 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I am interested in guidance and/or recommendations for ingesting log data from a data lake using tools available through Security Onion. Ideally, my team will push all data to the data lake and then we will use Security Onion features for ingest, analysis, reporting, etc.
Beta Was this translation helpful? Give feedback.
All reactions