Cyb3rWard0g / HELK

The Hunting ELK
GNU General Public License v3.0
3.73k stars 675 forks source link

Indexme override rule? #529

Closed priamai closed 3 years ago

priamai commented 3 years ago

Describe the problem

I am not sure I quite understand the logstash pipeline, I have a few points that should be clarified:

Why the last two have the same order 11? The 71 rule will override the 11 rule. Is this intentional?

Cyb3rWard0g commented 3 years ago

Hello @priamai !

First i would like to say thank you very much for helping us troubleshoot some of the current issues. I disconnected a little bit at the end of the year and then had a busy January. thank you for your patience.

Regarding the logstash pipeline,

0098-all-filter.cong

11-helk-indexme.json: and *71-helk-indexme-zeek.json

priamai commented 3 years ago

Hi @Cyb3rWard0g , thanks for the clarification and welcome back!

neu5ron commented 3 years ago

@priamai it's to handle a specific issue - this file will be overwritten eventually when I merged the whole OSSEM I built for zeek. let me know if have any other questions