Skip to content

linux log formats #4440

Closed Answered by nasbench
yadheen asked this question in Q&A
Sep 13, 2023 · 2 comments · 6 replies
Discussion options

You must be logged in to vote

Ah you're talking about the logsource field. Basically you can check the taxonomy file which contains all the currently supported logsources https://github.com/SigmaHQ/sigma-specification/blob/main/Taxonomy_specification.md

The difference between category, service and product can be found here https://github.com/SigmaHQ/sigma-specification/blob/main/Sigma_specification.md#log-source

Basically the the builtin folder contains rules that are from logs that are generated by builtin services. The other such as "process_creation" / "file_event" / "network_connection" are generic mappings based on Sysmon for linux or any similar EDR like tool that can generate those events.

Hope this clear thing…

Replies: 2 comments 6 replies

Comment options

You must be logged in to vote
5 replies
@yadheen
Comment options

@nasbench
Comment options

Answer selected by nasbench
@yadheen
Comment options

@nasbench
Comment options

@yadheen
Comment options

Comment options

You must be logged in to vote
1 reply
@nasbench
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants