Sunset suricata for zeek #14

Open
opened 2020-09-14 20:13:33 -05:00 by DarkFeather · 1 comment
Owner

Behavioral detection may be more reliable than signature, simply because signatures fall out of date or are written poorly.

Might be a good idea to file zeek directly into Graylog for AniNIX/Sharingan, rather than slurping Suricata's fast.log.

Behavioral detection may be more reliable than signature, simply because signatures fall out of date or are written poorly. Might be a good idea to file zeek directly into Graylog for AniNIX/Sharingan, rather than slurping Suricata's fast.log. * https://docs.zeek.org/en/current/examples/scripting/index.html#custom-logging * https://marketplace.graylog.org/addons/5e6cf3c6-7bdc-4a2c-bdca-441407e4a016
DarkFeather added the
On-hold
label 2022-05-04 06:55:26 -05:00
Author
Owner

So far, zeek has failed in maat.aninix.net -- it causes OOM issues. We'll stick with suricata until we have time to revisit this.

So far, zeek has failed in maat.aninix.net -- it causes OOM issues. We'll stick with suricata until we have time to revisit this.
DarkFeather added this to the Kanban project 2022-08-04 00:40:39 -05:00
Sign in to join this conversation.
No description provided.