You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Modern Honey Network
Hi,
I'm looking for a solution to send MHN alerts through syslog to a SIEM (IBM QRadar).
I plan to use rsyslog to send logs to QRadar. But I don't find log files with alerts.
Thanks for your help.
Jason Trost
unread,
Dec 27, 2015, 11:00:18 AM12/27/15
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to antoni...@gmail.com, Modern Honey Network
There are 3 scripts you could run depending on the format of the data you wanted for your SIEM. Each of these scripts will install and configure hpfeeds-logger.
The scripts are here: /opt/mhn/scripts
They are:
install_hpfeeds-logger-arcsight.sh logs to /var/log/mhn/mhn-arcsight.log as CEF
install_hpfeeds-logger-json.sh logs to /var/log/mhn/mhn-json.log as JSON
install_hpfeeds-logger-splunk.sh logs to /var/log/mhn/mhn-splunk.log as keyvalue pairs.
Jason Trost | VP of Threat Research | www.threatstream.com 2317 Broadway, 3rd Floor| Redwood City, CA 94063 Phone: 386.235.0078 | Twitter: @jason_trost
Antonin Hily
unread,
Dec 27, 2015, 11:38:54 AM12/27/15
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Modern Honey Network, antoni...@gmail.com
Hi,
thanks for your reply. I activated Splunk hpfeeds.
It works, and I can receive logs (on QRadar and an ELK external server). But it seems that the logs are not trained in the same way.
Here are 4 examples (sent to my ELK from MHN server (mhn-splunk.log)):
Do you have an idea on how to create a good filter for logstash? Because it's the same flow of logs, so I can't create type.
Many thanks for your help.
Antonin
Le dimanche 27 décembre 2015 17:00:18 UTC+1, Jason Trost a écrit :
There are 3 scripts you could run depending on the format of the data you wanted for your SIEM. Each of these scripts will install and configure hpfeeds-logger.
The scripts are here: /opt/mhn/scripts
They are:
install_hpfeeds-logger-arcsight.sh logs to /var/log/mhn/mhn-arcsight.log as CEF
install_hpfeeds-logger-json.sh logs to /var/log/mhn/mhn-json.log as JSON
install_hpfeeds-logger-splunk.sh logs to /var/log/mhn/mhn-splunk.log as keyvalue pairs.
Jason Trost | VP of Threat Research | www.threatstream.com 2317 Broadway, 3rd Floor| Redwood City, CA 94063 Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Modern Honey Network, antoni...@gmail.com
Hi Jason,
thanks for your reply and your help.
I was using theJSONformat.But strangely,it was not working. I finally foundout why. It was enough toput the tagto true inrsyslog.conf $InputFileTag true
There are sometimes stillerrorsto be addressed: "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [timestamp]", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Invalid format: \"Dec 28 08:17:01\""}}}}, :level=>:warn}
Jason Trost | VP of Threat Research | www.threatstream.com 2317 Broadway, 3rd Floor| Redwood City, CA 94063 Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Antonin Hily, Modern Honey Network
Do you have an example record that causes the timestamp error? Unless something is modifying the timestamp field it should never be in that format. See this line that sets it:
Jason Trost | VP of Threat Research | www.threatstream.com 2317 Broadway, 3rd Floor| Redwood City, CA 94063 Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.
Jason Trost | VP of Threat Research | www.threatstream.com 2317 Broadway, 3rd Floor| Redwood City, CA 94063 Phone: 386.235.0078 | Twitter: @jason_trost
--
You received this message because you are subscribed to the Google Groups "Modern Honey Network" group.