Skip to content
Discussion options

You must be logged in to vote

From https://docs.securityonion.net/en/2.3/syslog.html:

If you want to send syslog from other devices, you should check to see if the device has an existing Filebeat module at https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html. If so, using the Filebeat module should provide some parsing by default.

Filebeat has a Zscaler module:
https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-zscaler.html

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants