Security-Onion-Solutions / securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
https://securityonion.net
3.22k stars 498 forks source link

FEATURE: Add Events table columns for zeek ssl and suricata ssl #12697

Closed dougburks closed 6 months ago

dougburks commented 6 months ago

Currently, we have Events table columns for event.dataset ssl. As a defender, I'd like to be more granular and have separate Events table columns for ssl logs from zeek and suricata.

dougburks commented 6 months ago

Tested and verified that Suricata SSL logs get appropriate columns: image