Differentiating Ghosts From Real Users #95
Unanswered
Lachrymosa
asked this question in
Q&A
Replies: 1 comment 2 replies
-
Lachrymosa, How exactly are you using logstash to collect the data from GHOSTS? We have been contemplating different options. Are you simply installing the program on your API server as well? |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello, I am trying to figure out if there is an established process to differentiate ghost generated activity from a real user. I am currently using logstash agent to collect sysmon logs. If an established process is not developed for this, what would you recommend as a best attempt? Really enjoying your project regardless!
Beta Was this translation helpful? Give feedback.
All reactions