-
Notifications
You must be signed in to change notification settings - Fork 12
Open
Description
Alan,
I'm trying to set up a logstash parser for Firepower Connection Events and they seem to not match the grok filtering in https://github.com/TheAlanNix/cisco-security-tools/blob/master/FirepowerLogstash/FirepowerLogstash.conf.
I understand this file is just a starting point and I was just curious if you had any good resources that you used to build this logstash config file? Assuming I can get to a properly parsing logstash config for these Firepower events, I'll send it over for you to review.
Thank you!
Ricky
Metadata
Metadata
Assignees
Labels
No labels