Skip to content
Discussion options

You must be logged in to vote

First, please note that you can already use the existing Kibana Host dashboard for Windows event logs:

Also note that you'll likely want to deploy Sysmon to your Windows endpoints and there is already a dedicated dashboard for that.

Finally, note that our Hunt interface gives you lots of capabilities for slicing and dicing your Windows event logs:
https://docs.securityonion.net/en/2.3/hunt.html

Replies: 3 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Comment options

You must be logged in to vote
1 reply
@dougburks
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants