Skip to content
Discussion options

You must be logged in to vote

https://docs.securityonion.net/en/2.3/playbook.html#security-subfield

"Playbook uses the .security subfield that is generated by a special analyzer (https://github.com/neu5ron/es_stk). This analyzer allows case insensitive wildcard searches and is designed specifically for security logs."

Can you share more details about what is not working?

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by defensivedepth
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants