Replies: 1 comment 3 replies
-
We'll have to add an issue for this to be corrected, but in the meantime, you could do something similar to whats in the https://github.com/Security-Onion-Solutions/securityonion/blob/master/salt/elasticsearch/files/ingest/zeek.common#L4-L21 (Lines 4,5,21) |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hi, I recently realized that the timestamp of windows events that come from a wazuh agent are set to the time when the events arrive to the SO manager. I would like it to be set to the systemTime field (when the event actually happened). How do I do so? Thanks
Beta Was this translation helpful? Give feedback.
All reactions