blueteamvillage / DC31-obsidian-sec-eng

MIT License
1 stars 0 forks source link

Configure velociraptor forensics remote logging #147

Open juju4 opened 1 year ago

juju4 commented 1 year ago

Per May 11th meeting, get velociraptor output to splunk and other logging via cribl

juju4 commented 1 year ago

References https://docs.velociraptor.app/artifact_references/pages/elastic.flows.upload/ https://docs.velociraptor.app/blog/2019/2019-12-08-velociraptor-to-elasticsearch-3a9fc02c6568/ https://docs.velociraptor.app/vql_reference/server/elastic_upload/ https://github.com/Velocidex/velociraptor/blob/master/vql/server/elastic.go

Note that there is a direct https://docs.velociraptor.app/artifact_references/pages/splunk.flows.upload/

juju4 commented 1 year ago

Test hunt finished for 4 hosts x2 not seeing data in cribl or local backupdirectory...

juju4 commented 1 year ago

https://github.com/blueteamvillage/DC31-obsidian-sec-eng/pull/148

juju4 commented 1 year ago

Configuration has been pushed but believe not functional. Review needed

juju4 commented 1 year ago

Configuration has been done but not functional Velociraptor collection done offline anyway, at least for Windows. To review for next year Moving to hold