Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
The documentation describes setting up Beats to forward to Malcolm.
We need to do the following:
verify the documentation that it's (still?) correct and accurate
For winlogbeat specifically, we should look into normalizing its output so that the windows even logs from fluent bit's winlog and winevtlog, the EVTX files uploaded and parsed and what winlogbeats puts out so it's all apples and apples as much as possible (and the dashboards work pretty much the same for all three).
The documentation describes setting up Beats to forward to Malcolm.
We need to do the following: