Sunset suricata for zeek #14

Open
opened 2 years ago by DarkFeather · 1 comments
Owner

Behavioral detection may be more reliable than signature, simply because signatures fall out of date or are written poorly.

Might be a good idea to file zeek directly into Graylog for AniNIX/Sharingan, rather than slurping Suricata's fast.log.

Behavioral detection may be more reliable than signature, simply because signatures fall out of date or are written poorly. Might be a good idea to file zeek directly into Graylog for AniNIX/Sharingan, rather than slurping Suricata's fast.log. * https://docs.zeek.org/en/current/examples/scripting/index.html#custom-logging * https://marketplace.graylog.org/addons/5e6cf3c6-7bdc-4a2c-bdca-441407e4a016
DarkFeather added the
On-hold
label 3 months ago
Poster
Owner

So far, zeek has failed in maat.aninix.net -- it causes OOM issues. We'll stick with suricata until we have time to revisit this.

So far, zeek has failed in maat.aninix.net -- it causes OOM issues. We'll stick with suricata until we have time to revisit this.
DarkFeather added this to the Kanban project 1 week ago
Sign in to join this conversation.
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date

No due date set.

Dependencies

This issue currently doesn't have any dependencies.

Loading…
There is no content yet.