sof-elk icon indicating copy to clipboard operation
sof-elk copied to clipboard

Configuration files for the SOF-ELK VM

Results 65 sof-elk issues
Sort by recently updated
recently updated
newest added

this is blocking testing of the `feature/ecs` branch in a new VM. While the fix something that needs to be handled upstream, I'm mentioning it here for awareness. Upstream issue:...

VM

Hi @philhagen ! Testing some IIS logs with username format domain.local\username and they seemed to fail parsing because of the '.' Example log ``` 2024-05-29 21:10:57 192.168.1.47 POST /FOO/some/path/login.aspx -...

I've pulled down the latest public VM and using it to analyze some Windows Event Logs. I used KAPE to collect and do initial parsing with the KAPE SOF-ELK module...

What is the optimal way to ingest offline copies of extracted Windows Event Logs (evtx files) into SOF-ELK? I love working in SOF-ELK, but I find myself in the situation...

Add conditional handling so e.g. logstash only restarts if its configuration files changed, etc. See https://stackoverflow.com/questions/4877306/list-changed-files-in-git-post-merge-hook