using SO for Logs analysis without taps / pcaps, what level of analysis is possible on different kinds of logs from network devices #9828
Replies: 1 comment 1 reply
-
If the syslog traffic of those devices is being sent by the network device you're monitoring with SO, Zeek will see and parse the syslog files. Otherwise, your other option is to send syslog to one of your sensors from those devices. Documentation can be found here: https://docs.securityonion.net/en/2.3/syslog.html?highlight=syslog |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello experts,
We are planning to start with SO for Network Log Analysis like from Zscaler, Netflow, WAF,other network device etc.
Im wondering what components can be leveraged for preliminary analysis of these ingested logs from different sources.
Does suricata / zeek work only incase of using taps/span ports for traffic pcaps and not with logs?
Can someone share thoughts please
Thank you
Beta Was this translation helpful? Give feedback.
All reactions