-
Hi, I have an interesting question regarding logs integration. If I directly integrate the Windows DNS and DHCP logs into the OpenSearch database using Logstash, will the correlation engine trigger alerts for rules related to DNS and DHCP? Thank you! Best regards, |
Beta Was this translation helpful? Give feedback.
Answered by
c3s4rfred
Aug 6, 2024
Replies: 1 comment 5 replies
-
Hi @agauttam, actually it won't, because there are no rules implemented for DHCP and DNS, but you can develop as many custom rules for that logs as you want and test them on the platform. Best regards |
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hi, @agauttam adding a new logstash instance is a complex thing to do, UTMStack logs collector is prepared to read database configurations, dynamically create the logstash http input ports redirection from agent to UTMStack, the agent receives the logs, categorize them and send them to the correct logstash port, so adding a new logstash won't do anything.