PaloAltoNetworks / minemeld

Main MineMeld documentation repo
379 stars 64 forks source link

Report as Output in MineMeld [Question] #22

Closed gumityolcu closed 6 years ago

gumityolcu commented 6 years ago

Hello,

First of all, I have to say that I am a newbie to the field and to MineMeld. Thus it is possible that my understanding of the subject is flawed or that my terminology is crooked.

I want to know if there is a prototype in MineMeld for an output node with reporting capabilities. That is, is it possible to generate a document/report in MineMeld for human use, for humans to consult and investigate?

Thanks in advance, Galip

servebeer commented 6 years ago

Hi Galip, I am not aware of this capability. What we have done is create a logstash output that sends the data to our syslog server. From there, a Splunk Universal Forwarder sends the data to our index cluster. Last, we have created some Splunk dashboards and reports from the data. If you don't have Splunk, this isn't helpful (sorry), but if you do have Splunk, this works pretty good.

Jon

gumityolcu commented 6 years ago

Thank you for the response, we will look into it.

I'm closing the issue as it is resolved.

Regards.