Skip to content

WEC Logs #35

Answered by wagga40
casimkhan asked this question in Q&A
Aug 26, 2022 · 1 comments · 2 replies
Discussion options

You must be logged in to vote

To handle JSONL sources, Zircolite flattens any JSON given, which allows conversion to a table in a SQLite in memory Db. The rules in SQL are executed on this Db to get matches.

The workflow is detailed here : Workflow.

Multiple factors can lead to your logs not being handled correctly, can you share a anonymized sample of your logs ?

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@wagga40
Comment options

@casimkhan
Comment options

Answer selected by wagga40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants