Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

log normalization #316

Open
birolemekli opened this issue Nov 15, 2018 · 3 comments
Open

log normalization #316

birolemekli opened this issue Nov 15, 2018 · 3 comments

Comments

@birolemekli
Copy link

Hello there. rsyslog my central server windows server audit logs apache logs pfsense logs. I need to normalize them. I have to normalize the web requests ssh logs audit logs and save them to different files. then I will carry out the attack detection by subjecting to correlation. How can liblognorm help me?

@davidelang
Copy link
Contributor

davidelang commented Nov 15, 2018 via email

@birolemekli
Copy link
Author

I would like to improve myself in the siem area. I collected Windows server, pfsense and web server logs with syslog.

I need to get the log files in the same format.

Windows Server Audit Logs
screenshot

Web Apache Logs

screenshot

Firewall Pfsense Logs

screenshot

Logs are saved in this way. I don't want to record more logs here.
The Windows server log is meaningless. I just want to make it simpler.
Then I will be able to make corrections and attack detection through these logs.
I need your help on this.
Can Liblognorm do this?

Can you help me?

@davidelang
Copy link
Contributor

davidelang commented Nov 18, 2018 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants