idaholab / Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
https://idaholab.github.io/Malcolm/
Other
327 stars 53 forks source link

allow artifact upload to handle windows event logs #465

Closed mmguero closed 3 weeks ago

mmguero commented 2 months ago

Currently the upload interface allows for uploading:

Although this departs a bit from Malcolm's bread-and-butter of network traffic, it's been requested by some users to allow the upload of files containing windows event logs, which should be processed similar to if they had been forwarded by fluent-bit.

Things to figure out:

mmguero commented 4 weeks ago
mmguero commented 3 weeks ago

Marking as "done" for now. There are things for future improvements, which we can talk about and track in other issues. Some of these might include: