Hello
Please How can I parse snort logs with grok pattern?
05/30-09:08:58.481608 [] [1:10000001:1] ICMP test detected [] [Classification: Generic ICMP event] [Priority: 3] {ICMP} @IP -> @IP
Many thanks
Hello
Please How can I parse snort logs with grok pattern?
05/30-09:08:58.481608 [] [1:10000001:1] ICMP test detected [] [Classification: Generic ICMP event] [Priority: 3] {ICMP} @IP -> @IP
Many thanks
Hi,
Im hoping that https://www.youtube.com/watch?v=SKSqPRwDfns will aid in your beginnings here.
and patterns here to aid build this out: https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/grok-patterns
If you google snort grok patterns you find plenty of keys come up along the way
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.