Advertisement
taosecurity

Troubleshooting EQL with Zeek Logs 04

Mar 18th, 2019
95
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.87 KB | None | 0 0
  1. so16@so16:~$ cat conn.log | python convert_logs.py
  2.  
  3. {"local_resp": true, "resp_bytes": 234, "uid": "CPQ9vC2my8sIGasb3a", "service": "dns", "proto": "udp", "orig_ip_bytes": 0, "duration": 0.000368, "orig_pkts": 0, "ts": "2019-03-14T23:59:49.920582Z", "resp_ip_bytes": 290, "resp_pkts": 2, "history": "^d", "conn_state": "SHR", "local_orig": true, "missed_bytes": 0, "sensorname": "so16-enp0s8", "id_resp_h": "192.168.4.1", "orig_bytes": 0, "id_resp_p": 53, "id_orig_p": 42051, "id_orig_h": "192.168.4.57"}
  4. {"local_resp": true, "id_resp_h": "192.168.4.18", "uid": "CiEbJY1e6EoUiEaBW4", "conn_state": "S0", "proto": "udp", "orig_ip_bytes": 76, "orig_pkts": 1, "ts": "2019-03-14T23:59:00.699642Z", "resp_ip_bytes": 0, "resp_pkts": 0, "local_orig": false, "missed_bytes": 0, "sensorname": "so16-enp0s8", "history": "D", "id_resp_p": 57878, "id_orig_p": 123, "id_orig_h": "173.230.144.109"}
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement