clong / DetectionLab

Automate the creation of a lab environment complete with security tooling and logging best practices
MIT License
4.57k stars 978 forks source link

Threathunting index is empty #502

Closed clong closed 3 years ago

clong commented 3 years ago

Figure out why events aren't populating correctly

clong commented 3 years ago

Oh man, found a huge issue while working through this. The sourcetype for sysmon events actually included double quotes in the actual field value which was causing all sorts of issues. Fix incoming.

clong commented 3 years ago

Screenshot after the latest commit:

image

Marking this fixed now. There's still some improvements to be made (adding whitelists, etc), but the bulk of the problems have been solved.