sysmonforlinux #14028
Replies: 2 comments 6 replies
-
Have you tried the Elastic Agent for Linux? It provides much of the same hunting capability as sysmon logs. https://docs.securityonion.net/en/2.4/downloads.html |
Beta Was this translation helpful? Give feedback.
-
Hello @defensivedepth , However, I would appreciate your feedback to confirm if the method I used is correct or if there are other alternatives. 1.Logs from Linux systems are collected through the "system" integration, which parses the system syslog logs using the "logs-system.syslog" pipeline. I would greatly appreciate it if you could confirm whether this approach is correct or if there are other options to consider. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello everyone,
I’m currently working with Security Onion 2.4.110, and I’m trying to integrate SysmonForLinux logs for hunting. However, I’m having some difficulty with parsing these logs properly for analysis in Security Onion.
SysmonForLinux Log Parsing:
I’ve installed SysmonForLinux and configured it to send logs to elasticsearch. But I’m struggling to properly parse and visualize these logs for effective threat hunting.
Question: What are the best practices or steps to properly parse SysmonForLinux logs in elasticsearch? Are there specific configurations or processors I need to set up in order to effectively analyze these logs?
Any guidance, tips, or documentation links would be greatly appreciated!
Thank you in advance for your help!
Best regards,
Hodan Dirieh
Beta Was this translation helpful? Give feedback.
All reactions