Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Send Actionable Alerts to SysLog Server #429

Open
AnthonyVO opened this issue Jan 27, 2023 · 0 comments
Open

Send Actionable Alerts to SysLog Server #429

AnthonyVO opened this issue Jan 27, 2023 · 0 comments

Comments

@AnthonyVO
Copy link

I am very impressed with SELKS and the visibility it provides into what is going on in my network environment. I have already made some network changes as a result.

I am currently using it in an IDP configuration watching a mirrored port on our core switch. We run predominantly a Windows environment.

I have set up my Syslog server (Syslog Watcher) so that it notifies me via Text if there is anything urgent that I need to deal with.

I would like to set up SELKS so that it pushes alerts to my remote Syslog server but I can't seem to get the pieces lined up.

I saw this issue where you talked about using LogStash but I am not sure how to proceed.

I also tried to have Suricata log to its Container Syslog, and then have the Docker Daemon push those logs to the server logs with it pushing to my remote Syslog server but that just created a massive mess of server alerts without any actionable Suricata alerts.

I am not in a position where I can monitor SELKS full time so I need a reliable way to receive alerts when there is something I need to attend to.

Any help would be much appreciated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant