So I got MHN forwarding events to splunk and it show attack count but no data for Cowrie is showing in dashboard. Would I be correct in assuming mhn splunk doesn't support cowrie? If not can it be added or is best to ditch cowrie in favor of kippo? ThanksJeff
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-net...@googlegroups.com.
To post to this group, send email to modern-hon...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/modern-honey-network/66d08f9f-de3b-4450-af0e-6ba06a8ebc79%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
That is correct but the changes needed to support cowrie are likely very small. Changing this file is likely all that is neededThe "type=kippo.sessions" needs to be "(type=kippo.sessions OR type=cowrie.sessions)"You can do these changes in your local instance of splunk if you simply customize the views.Ultimately Anomali will need to make these changes since they own this splunk app.
On Fri, Feb 17, 2017 at 11:53 PM Jeffery W <jeff.mag...@gmail.com> wrote:
So I got MHN forwarding events to splunk and it show attack count but no data for Cowrie is showing in dashboard. Would I be correct in assuming mhn splunk doesn't support cowrie? If not can it be added or is best to ditch cowrie in favor of kippo? Thanks--Jeff
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
To unsubscribe from this group and stop receiving emails from it, send an email to modern-honey-network+unsub...@googlegroups.com.