Тёмный

Standardize Your SIEM Logs Now! 

Taylor Walton
Подписаться 19 тыс.
Просмотров 5 тыс.
50% 1

Join me as we continue on to Phase 9 of the World's Best SIEM Stack Series, normalizing our ingested logs to common field names with Graylog!
Blog Post: / part-9-log-normalization
🚩 CTF Challenge: ctf.socfortres...
📩 Contact Me: taylor.walton@socfortress.co
ℹ️ LinkedIn: / socfortressmdr
🧾 Our Blog: / socfortress
☕ Buy Me A Coffee: bit.ly/3woh21M
🚀 Security Operations Center as a Service: www.socfortres...
✅ Free For Life Tier: www.socfortres...
👨🏻‍💻 Professional Services: www.socfortres...
👾 Discord Channel: / discord
Series Playlist: • World's Best SIEM Stack

Опубликовано:

 

2 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 12   
@aayushghimire1434
@aayushghimire1434 Год назад
Also where the part where you created the GeoIP lookup:data_win_eventdata_destinationIp pipeline rules ???
@maximojimeno
@maximojimeno Год назад
could you find the solution? I have the same problem
@enderst81
@enderst81 Год назад
I must have missed where we installed Sysmon for Linux. BTW this has been an awesome series.
@taylorwalton_socfortress
@taylorwalton_socfortress Год назад
Haven’t covered that but there is an install guide in the repo: github.com/Sysinternals/SysmonForLinux
@monkinsane
@monkinsane 8 месяцев назад
@@taylorwalton_socfortress Could you please share your linux sysmon config.xml file?
@maximojimeno
@maximojimeno Год назад
en que parte configura el GeoIP lookup:data_win_eventdata_destinationIp pipeline rules ?
@1222dss
@1222dss Год назад
is there any way to normalize logs within Wazuh? I've run into similar problem with Suricata logs where IP had different syntax and extracted field couldn't be used by active responses.
@taylorwalton_socfortress
@taylorwalton_socfortress Год назад
Hey Kotory, you can but it is alittle complicated, you will need to create a custom wazuh decoder to match on the field name that suricata writes the destination ip to and map that to `dst_ip` (or whatever field name wazuh needs for the default active response - i forgot what that is off the top of my head).
@maximojimeno
@maximojimeno Год назад
I had the same problem and I was able to solve it with this rule "GreyNoise Lookup on DestIP" when has_field("dst-ip") then let ldata = lookup( rename_field("dst-ip", "DestIP"); lookup_table: "greynoise", key: to_string($message.DestIP) ); set_fields( fields: ldata, prefix: "greynoise_" ); end
@monkinsane
@monkinsane 8 месяцев назад
Hi, First of all - thanx for the vids. Just wondering why your using sysmon for linux when your howto on agent install install packetbeat? This causes the linux normalization to not work for people following your howto.
@leoasis11
@leoasis11 Год назад
Thank you for sharing your knowledge, love the vid
@vinyldown8490
@vinyldown8490 Год назад
This is dooope!! ty
Далее
MISP Install - 1 Million (+) Free IoCs in 10 Minutes!
22:17
When Goalkeepers Get Bored 🤯 #3
00:27
Просмотров 1,1 млн
ХОККЕЙНАЯ КЛЮШКА ИЗ БУДУЩЕГО?
00:29
host ALL your AI locally
24:20
Просмотров 1,1 млн
When you Accidentally Compromise every CPU on Earth
15:59
The cloud is over-engineered and overpriced (no music)
14:39
Detecting Abnormal Network Connections With Wazuh
14:16
When Goalkeepers Get Bored 🤯 #3
00:27
Просмотров 1,1 млн