-
Notifications
You must be signed in to change notification settings - Fork 406
Closed
Labels
enhancementNew feature or requestNew feature or requestlogstashRelating to Malcolm's use of LogstashRelating to Malcolm's use of LogstashnetboxRelated to Malcolm's use of NetBoxRelated to Malcolm's use of NetBox
Milestone
Description
For performance and storage reasons, not every log type is netbox-enriched. However, we've added a few more types to the list (new ones in bold italics):
- suricata.alert
- zeek.conn
- zeek.dce_rpc
- zeek.dhcp
- zeek.dns
- zeek.known_hosts
- zeek.known_services
- zeek.login
- zeek.ntlm
- zeek.notice
- zeek.rdp
- zeek.rfb
- zeek.signatures
- zeek.smb_cmd
- zeek.smb_files
- zeek.smb_mapping
- zeek.software
- zeek.ssh
- zeek.weird
The reason for the change is to improve the data we have for tracking lateral movement (which is often done with protocols like rdp, vnc, ssh, etc.)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestlogstashRelating to Malcolm's use of LogstashRelating to Malcolm's use of LogstashnetboxRelated to Malcolm's use of NetBoxRelated to Malcolm's use of NetBox
Type
Projects
Status
Released