cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

Cyber Elite
Cyber Elite

@EduRamirez,

I'm not aware of a resource where this is specifically detailed, but if you're using a normal SIEM (Graylog, Splunk, LogRythm, etc.) have their respective content packs that you can utilize  instead of having to build it out manually. If you've rolled your own maybe you can use Graylogs content pack to build out your extractors? 

View solution in original post

Who rated this post