[Bro] sending event log output to a database

Seth Hall seth at icir.org
Tue Mar 19 18:14:24 PDT 2013


On Mar 19, 2013, at 8:47 PM, Ron King <roncking at gmail.com> wrote:

> Hi, I want to send event log data directly to a nosql database. Where
> in the code should I look in order to add this capability?


We already support directly writing to ElasticSearch.  Look in src/logging/writers.

What database did you want to add support for?

  .Seth

--
Seth Hall
International Computer Science Institute
(Bro) because everyone has a network
http://www.bro.org/





More information about the Bro mailing list