Standardize Your SIEM Logs Now!

  Рет қаралды 5,430

Taylor Walton

Taylor Walton

Күн бұрын

Пікірлер: 12
@aayushghimire1434
@aayushghimire1434 2 жыл бұрын
Also where the part where you created the GeoIP lookup:data_win_eventdata_destinationIp pipeline rules ???
@maximojimeno
@maximojimeno Жыл бұрын
could you find the solution? I have the same problem
@enderst81
@enderst81 2 жыл бұрын
I must have missed where we installed Sysmon for Linux. BTW this has been an awesome series.
@taylorwalton_socfortress
@taylorwalton_socfortress 2 жыл бұрын
Haven’t covered that but there is an install guide in the repo: github.com/Sysinternals/SysmonForLinux
@monkinsane
@monkinsane 11 ай бұрын
@@taylorwalton_socfortress Could you please share your linux sysmon config.xml file?
@leoasis11
@leoasis11 2 жыл бұрын
Thank you for sharing your knowledge, love the vid
@maximojimeno
@maximojimeno Жыл бұрын
en que parte configura el GeoIP lookup:data_win_eventdata_destinationIp pipeline rules ?
@vinyldown8490
@vinyldown8490 Жыл бұрын
This is dooope!! ty
@monkinsane
@monkinsane 11 ай бұрын
Hi, First of all - thanx for the vids. Just wondering why your using sysmon for linux when your howto on agent install install packetbeat? This causes the linux normalization to not work for people following your howto.
@1222dss
@1222dss 2 жыл бұрын
is there any way to normalize logs within Wazuh? I've run into similar problem with Suricata logs where IP had different syntax and extracted field couldn't be used by active responses.
@taylorwalton_socfortress
@taylorwalton_socfortress 2 жыл бұрын
Hey Kotory, you can but it is alittle complicated, you will need to create a custom wazuh decoder to match on the field name that suricata writes the destination ip to and map that to `dst_ip` (or whatever field name wazuh needs for the default active response - i forgot what that is off the top of my head).
@maximojimeno
@maximojimeno Жыл бұрын
I had the same problem and I was able to solve it with this rule "GreyNoise Lookup on DestIP" when has_field("dst-ip") then let ldata = lookup( rename_field("dst-ip", "DestIP"); lookup_table: "greynoise", key: to_string($message.DestIP) ); set_fields( fields: ldata, prefix: "greynoise_" ); end
MISP Install - 1 Million (+) Free IoCs in 10 Minutes!
22:17
Taylor Walton
Рет қаралды 54 М.
Best SIEM Logging With Graylog - Routing SIEM Logs with Graylog!
17:11
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 700 М.
99.9% IMPOSSIBLE
00:24
STORROR
Рет қаралды 31 МЛН
How to Build Your First MISP Instance From Scratch
13:56
Adam Goss
Рет қаралды 2,6 М.
Wazuh + MISP Automation - Automate Your SIEM Threat Intel Now!
19:31
Graylog Install - Best Log Ingester for Your SIEM!
31:18
Taylor Walton
Рет қаралды 31 М.
All Rust string types explained
22:13
Let's Get Rusty
Рет қаралды 195 М.
What Is SIEM?
4:29
IBM Technology
Рет қаралды 114 М.
Top 10 FREE OSINT tools (with demos) for 2024 - And FREE OSINT course!
1:08:19
What is a SIEM solution? How SIEM works and Architecture?
27:34
Relative Security
Рет қаралды 112 М.