RackSec / desdemona

Data-backed security operations
Eclipse Public License 1.0
2 stars 7 forks source link

Normalization of ingested syslog data #50

Open ehashman opened 8 years ago

ehashman commented 8 years ago

We need to determine a standardized schema for all our ingested data from syslog.

In particular, we want to ensure that each log entry/alert (hereafter "event") is annotated with:

lvh commented 8 years ago

Source and destination IPs/ports seem like they'd be specific to some kinds of events.

I'm not sure how to make this ticket actionable. It seems like it would be a per-source bit of mangling.

lvh commented 8 years ago

I am making this about syslog to make it actionable, and adding it to durable storage because that's where we really care.

lvh commented 8 years ago

This might be a convenient location to pick roughly the same things Metron picks.