tcp-honeypot.py Logstash Parser & Dashboard Update
This is an update for logstash and dashboard published in January for Didier's tcp-honeypot.py honeypot script. The parser has been updated to follow the Elastic Common Schema (ECE) format, parsing more information from the honeypot logs that include revised and additional dashboards.
tcp-honeypot Log Analysis from Discover
tcp-honeypot Dashboard Summary
The file tcp-honeyport parser can be downloaded here and the dashboard JSON here.
[1] https://isc.sans.edu/forums/diary/ELK+Dashboard+and+Logstash+parser+for+tcphoneypot+Logs/25702
[2] https://www.elastic.co/guide/en/ecs/current/ecs-reference.html
[3] https://handlers.sans.edu/gbruneau/elastic.htm
-----------
Guy Bruneau IPSS Inc.
My Handler Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu
Comments
Anonymous
Jun 28th 2020
4 years ago
Anonymous
Jun 28th 2020
4 years ago