Skip to content
Discussion options

You must be logged in to vote

Typically, these kinds of integrations are easier if you can leverage an existing Filebeat module, but I'm not sure if the Barracuda module would work for you:
https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-barracuda.html
https://docs.securityonion.net/en/2.3/filebeat.html

If necessary, you could always write your own custom ingest parser:
https://docs.securityonion.net/en/2.3/elasticsearch.html#parsing

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@esbat-max
Comment options

@dougburks
Comment options

@esbat-max
Comment options

@esbat-max
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants