Sysmon Host Data (Where to send it) #1986
Replies: 1 comment
-
You would send it to your Manager. Also see https://docs.securityonion.net/en/2.3/beats.html?highlight=winlogbeat#winlogbeat. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I have a new deployment request from a client and would only like to gather host logs from windows machines, specifically sysmon logs. I have winlogbeats, sysmon, and deployment methods ready to go. Where is the best location to send host data via port 5044? Master, search nodes, or fwd nodes? Any guidance would be must appreciated. Thanks in advance.
Beta Was this translation helpful? Give feedback.
All reactions