Can it parse Zeek logs to identify long-running TCP connections and/or identify user attempts to access a DNS blocked domain?
We could totally add that, but no one's asked for it so far
31–32 of 32 posts
Can it parse Zeek logs to identify long-running TCP connections and/or identify user attempts to access a DNS blocked domain?
I took a cursory look and I like what I see – the service maps are really good, I love the level of detail. I will say, one thing I'm looking for with this kind of software, to maximise value, is structured logging support, and from what I could see, each log line just has the raw payload currently. Is that something you have on your roadmap?