In this video we demonstrate how to configure an Output in LimaCharlie to send your telemetry anywhere.
LimaCharlie users can relay their data anywhere they want for longer term storage and analysis. Where that data is sent depends on which Outputs are activated. You can have as many Output modules active as you want. For example you can send varying levels of data to multiple syslog destinations using the Syslog Output module and then send additional data to some cold storage over an Scp Output module.
Output is split between four categories: "event", "detect", "audit" and "deployment". Selecting a Stream when creating an Output will select the relevant type of data to flow through it.
Exact configuration possibilities in the Output section: https://doc.limacharlie.io/docs/docum...
----------------------------------
General Links
----------------------------------
Website: https://limacharlie.io
Documentation: https://doc.limacharlie.io/
Free Education: https://edu.limacharlie.io/
----------------------------------
Course Playlists
----------------------------------
Basic Detection & Response: • Basic Detection & Response
Advanced Detection & Response: • Advanced Detection & Response
Secure Access Service Edge: • Playlist
Leveraging Community Resources: • Leveraging the CLI & SDK
Setting up An MSSP: • Setting Up An MSSP with LimaCharlie
Using the CLI & SDK: • Leveraging the CLI & SDK
Ingesting Log Files & Artifacts: • Ingesting and Processing Artifacts (Window...
Zeek Network Monitoring: • Network Artifacts & Zeek
Incident Response: • DFIR
Real-time Windows Event Logs: • Ingesting Windows Event Logs
Responding to HAFNIUM: • HAFNIUM
The Add-on Marketplace: • Add-on Marketplace
----------------------------------
Social Media
----------------------------------
Community Slack Channel: https://slack.limacharlie.io/
Twitter: / limacharlieio
Reddit: / limacharlieio
LinkedIn: / limacharlieio
YouTube: / limacharlieio
Github: https://github.com/refractionPOINT