Skip to content

Custom FTP Syslog and Alerts in SOC Console #9212

Locked Answered by dougburks
Wilks2222 asked this question in Q&A
Discussion options

You must be logged in to vote

Once you have parsed the logs, one option might be to use Playbook to define criteria for alerts:
https://docs.securityonion.net/en/2.3/playbook.html

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by Wilks2222
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants