Sunset suricata for zeek #14

Open
opened 2020-09-14 20:13:33 -05:00 by DarkFeather · 1 comment

Behavioral detection may be more reliable than signature, simply because signatures fall out of date or are written poorly.

Might be a good idea to file zeek directly into Graylog for AniNIX/Sharingan, rather than slurping Suricata's fast.log.

Behavioral detection may be more reliable than signature, simply because signatures fall out of date or are written poorly. Might be a good idea to file zeek directly into Graylog for AniNIX/Sharingan, rather than slurping Suricata's fast.log. * https://docs.zeek.org/en/current/examples/scripting/index.html#custom-logging * https://marketplace.graylog.org/addons/5e6cf3c6-7bdc-4a2c-bdca-441407e4a016
DarkFeather added the
On-hold
label 2022-05-04 06:55:26 -05:00

So far, zeek has failed in maat.aninix.net -- it causes OOM issues. We'll stick with suricata until we have time to revisit this.

So far, zeek has failed in maat.aninix.net -- it causes OOM issues. We'll stick with suricata until we have time to revisit this.
DarkFeather added this to the Kanban project 2022-08-04 00:40:39 -05:00
Sign in to join this conversation.
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: AniNIX/Ubiqtorate#14
There is no content yet.