I have a question about exporting BRO DNS data from an ELSA query. I'm looking to export reports (class=BRO_DNS dstport="53") on a daily or weekly basis that can then be ran against some other tools. For example, I just did a test for the last day and a half, this is what returned:
Records: 100 / 2680912 1845 ms
Is there a way to directly export a query with all results to one of the export data types (Excel, etc.)?
I also tried setting up ELSA to send email results from the batch, but the batch never returns results. Email received below:
0 results for query class=BRO_DNS dstport=53 limit:50000 https://SO-Server-IP/elsa//get_results?qid=1005&hash=25af6174a0fcecc4d346680a72b7ce644b9a88e8
Also, that link 404s for me. Below is my ELSA email config in elsa_web.conf:
"email": {
"smtp_server": "my smtp",
"to": "user...@blahblah.com",
"display_address": "ELSA-...@blahblah.com",
"base_url": "https://SO-Server-IP/elsa/",
"subject": "ELSA Alert"
},
Thanks and any help is really appreciated
Damon
--
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/1Q43jHnPemM/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/d/optout.