Bro Logs Ingestion
David Decker <[email protected]>
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAE44EXGaF3o9PR1mokTNJDNea3N_UEfRpYXWpfLEZfezmZOvQA@mail.gmail.com> |
Sorry beginner question here: But I know you can ingest logs into Splunk, and Elastic Search. So I know SecurityOnion has an ELK stack and it looks like they get sent right to Logstash - ES - Kibana RockNSM looks almost the same but it has a stop off at Kafka before forwarding to Logstash. Trying to figure out is there a benefit for Kafka. Also looking at using Splunk instead of ES. I know I can use the TA and monitor the logs from splunk, but would it be better to monitor from Kafka? I guess I need to understand more of how Kafka fits. Thanks Dave _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek