-
Hi, <14>Nov 21 18:40:13 TEST-FTP CrushFTP.log:POST|11/21/2022 18:40:12.498|[HTTPS:29741_60179:test_user:10.10.10.1] WROTE: HTTP/1.1 200 OK Thanks |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Once you have parsed the logs, one option might be to use Playbook to define criteria for alerts: |
Beta Was this translation helpful? Give feedback.
Once you have parsed the logs, one option might be to use Playbook to define criteria for alerts:
https://docs.securityonion.net/en/2.3/playbook.html