Bro Logs Ingestion

David Decker <[email protected]>
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAE44EXGaF3o9PR1mokTNJDNea3N_UEfRpYXWpfLEZfezmZOvQA@mail.gmail.com>
Sorry beginner question here:

But I know you can ingest logs into Splunk, and Elastic Search.

So I know SecurityOnion has an ELK stack and it looks like they get sent
right to Logstash - ES - Kibana

RockNSM looks almost the same but it has a stop off at Kafka before
forwarding to Logstash.

Trying to figure out is there a benefit for Kafka.

Also looking at using Splunk instead of ES.
I know I can use the TA and monitor the logs from splunk, but would it be
better to monitor from Kafka?

I guess I need to understand more of how Kafka fits.

Thanks
Dave

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.