Skip to content
Discussion options

You must be logged in to vote

If you use a specific integration for a specific log type, then the logs will be fully parsed allowing you to slice and dice all of the fields separately in our user interfaces like Dashboards and Hunt.

If you don't use a specific integration, but instead use plain syslog, then the logs will not be parsed by default and you would need to develop your own parsers from scratch.

We recommend using a specific integration so that you get fully parsed logs without additional effort.

For more information, please see:
https://docs.securityonion.net/en/2.4/syslog.html
https://docs.securityonion.net/en/2.4/third-party-integrations.html

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@udi-mosh
Comment options

Answer selected by udi-mosh
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants