Skip to content
#

siem

Here are 92 public repositories matching this topic...

vburov
vburov commented Apr 17, 2019

Event with ID = 7045 from System log has incorrect source in section "Software and Service Installation" of "Recommended Events to Collect" document.
Correct source for this event is "Service Control Manager":

  • Provider
    [ Name] Service Control Manager
    [ Guid] {555908d1-a6d7-4695-8e1e-26931d2012f4}
    [ EventSourceName] Service Control Manager
  • EventID 7045
    Also, I create
bug
candlerb
candlerb commented Oct 29, 2019

Is your feature request related to a problem? Please describe.

I have some issues around the "date" and "time" fields which come from syslog, either as pipe-delimited fields or as mapped JSON fields.

The fundamental question is: are these fields actually used for anything, apart from being included in alert messages? And does it matter if the format is not YYYY-MM-DD or HH:MM:SS?

**

EdgeSync
EdgeSync commented Feb 28, 2020

Hi DSIEM people,

Not really an issue per-se, but I'm struggling to understand how you actually implement Intel Feeds for DSIEM.

From what I can gather, you are using Wise for Moloch to collect intel from various sources. But what I'm having trouble understanding is how you grab the normalized event, and then check the data in that event against a piece of intel.

I have read https://githu

Improve this page

Add a description, image, and links to the siem topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the siem topic, visit your repo's landing page and select "manage topics."

Learn more

You can’t perform that action at this time.