Skip to content

importing stored sysmon events (json) #1948

Discussion options

You must be logged in to vote

Hey, if it does not meet the requirements, it will not be possible to import it using the web ui.

There are other methods to import them, e.g. https://timesketch.org/developers/api-upload-data/ which does require some coding.

Depending on the sysmon source, it might be possible to run it via plaso to get it in a format that is accepted from Timesketch. Besides that we are trying to stay away from being to open for formats because it very quickly becomes very complicated to keep up with all the different parsers, data formats and so on.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@splunk-user1
Comment options

Answer selected by jaegeral
Comment options

You must be logged in to vote
1 reply
@splunk-user1
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants