Differentiating Ghosts From Real Users #95
Unanswered
Lachrymosa
asked this question in
Q&A
Replies: 1 comment 2 replies
-
Lachrymosa, How exactly are you using logstash to collect the data from GHOSTS? We have been contemplating different options. Are you simply installing the program on your API server as well? |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello, I am trying to figure out if there is an established process to differentiate ghost generated activity from a real user. I am currently using logstash agent to collect sysmon logs. If an established process is not developed for this, what would you recommend as a best attempt? Really enjoying your project regardless!
Beta Was this translation helpful? Give feedback.
All reactions