Replies: 1 comment 2 replies
-
Yep, Chainsaw can work on JSON but it would need a different mapping file if you wish to run it on sigma rules, etc. This is because it needs to know how to map the fields as the json fields are probably different to those in the raw evtx. Additionally chainsaw's native rules are all evtx only at the moment, for the same reason. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have a Wazuh Server with multiple endpoints, and I cannot install Chainsaw on each endpoint. So, I want to install Chainsaw on the machine running the Wazuh Server only. In that case, I will collect the logs of all the endpoints, and the Wazuh Server will forward these logs Chainsaw in JSON format because that's the log format output for Wazuh. The documentation says that Chainsaw can output the results in JSON format. However, my question is, can Chainsaw read JSON as an input format?
Beta Was this translation helpful? Give feedback.
All reactions