Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SysmonSearch for Nxlog #8

Open
V1D1AN opened this issue Jul 15, 2020 · 1 comment
Open

SysmonSearch for Nxlog #8

V1D1AN opened this issue Jul 15, 2020 · 1 comment

Comments

@V1D1AN
Copy link

V1D1AN commented Jul 15, 2020

Hello,

If I want test SysmonSearch with a Nxlog and a logstash.
I must change my winlogbeat.yml of sigma with my nxlog.yml and change the "collection_alert_data.py" and "collection_statistical_data.py" ?

Congratulations on your work

@S03D4-164
Copy link
Collaborator

Connecting with a Nxlog sounds interesting, but I think it needs large-scale rewriting.

Although SysmonSearch has the yml of sigma, there are still a lot of hardcoded winlogbeat field names in the source...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants