davehull / Kansa

A Powershell incident response framework
Apache License 2.0
1.55k stars 266 forks source link

Update Kansa to add additional output options #186

Closed dmoore44 closed 5 years ago

dmoore44 commented 5 years ago

I always thought that manually analyzing csv or json files (or even using command line tools for analysis) was a pain, and that Kansa could be massively improved by adding the ability to send output to Splunk. So, I added the ability output to Splunk and GrayLog (sorry, no ELK endpoint for now... maybe later).

By adding Splunk and GrayLog as output options, Kansa output can now be analyzed right alongside other centrally logged data - awesome!