Sunset suricata for zeek #14

开启中
DarkFeather2020-09-14 20:13:33 -05:00创建 · 1 评论
管理员

Behavioral detection may be more reliable than signature, simply because signatures fall out of date or are written poorly.

Might be a good idea to file zeek directly into Graylog for AniNIX/Sharingan, rather than slurping Suricata's fast.log.

Behavioral detection may be more reliable than signature, simply because signatures fall out of date or are written poorly. Might be a good idea to file zeek directly into Graylog for AniNIX/Sharingan, rather than slurping Suricata's fast.log. * https://docs.zeek.org/en/current/examples/scripting/index.html#custom-logging * https://marketplace.graylog.org/addons/5e6cf3c6-7bdc-4a2c-bdca-441407e4a016
DarkFeather2022-05-04 06:55:26 -05:00 添加了标签
On-hold
作者
管理员

So far, zeek has failed in maat.aninix.net -- it causes OOM issues. We'll stick with suricata until we have time to revisit this.

So far, zeek has failed in maat.aninix.net -- it causes OOM issues. We'll stick with suricata until we have time to revisit this.
DarkFeather 将此添加到 Kanban 项目 2022-08-04 00:40:39 -05:00
登录 并参与到对话中。
没有提供说明。