Skip to content

Failed to detect JSONL log #49

Answered by wagga40
tpseers asked this question in Q&A
Jan 18, 2023 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

Hello,

I think this is because your rule is just a yaml to json conversion. It seems it has not been converted to Zircolite (more precisly SQLite) format. The related docs are here : https://github.com/wagga40/Zircolite/blob/master/docs/Usage.md#sysmon-rulesets-when-investigated-endpoints-have-sysmon-logs

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@tpseers
Comment options

Answer selected by wagga40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants