importing stored sysmon events (json) #1948
-
Possible to import sysmon events stored as json ? Since it does not meet 1 of the mandatory requirements Also the timestamp format is Thank you |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
Hey, if it does not meet the requirements, it will not be possible to import it using the web ui. There are other methods to import them, e.g. https://timesketch.org/developers/api-upload-data/ which does require some coding. Depending on the sysmon source, it might be possible to run it via plaso to get it in a format that is accepted from Timesketch. Besides that we are trying to stay away from being to open for formats because it very quickly becomes very complicated to keep up with all the different parsers, data formats and so on. |
Beta Was this translation helpful? Give feedback.
-
Another solutoion here is to ust run the Sysmon evtx files in Plaso and import it that way. That also has the benefit of setting data_type correctly, and parsing out eventid etc. I'm curious: @splunk-user1 what is the use case for exporting to json instead of getting the original evtx files? |
Beta Was this translation helpful? Give feedback.
Hey, if it does not meet the requirements, it will not be possible to import it using the web ui.
There are other methods to import them, e.g. https://timesketch.org/developers/api-upload-data/ which does require some coding.
Depending on the sysmon source, it might be possible to run it via plaso to get it in a format that is accepted from Timesketch. Besides that we are trying to stay away from being to open for formats because it very quickly becomes very complicated to keep up with all the different parsers, data formats and so on.