outflanknl / RedELK

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
BSD 3-Clause "New" or "Revised" License
2.35k stars 371 forks source link

Bluecheck content parsing and alarm #228

Open MarcOverIP opened 2 years ago

MarcOverIP commented 2 years ago

Bluecheck output should be fully parsed by Logstash, and alarms should be made. Data is sent to dedicated bluecheck-* index

MarcOverIP commented 2 years ago

Tracked in branch bluecheck-update