microsoft / microsoft/SysmonForLinux

Support for Alternative Log Format such as JSON

オープン
#4 コメント 13 件 リアクション 17 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

enhancement
主要言語
C
スター
2.2k
フォーク
220
平均マージ
11日 22時間
マージ済み PR(30日)
2

説明

Is it possible for this project to get JSON support? Windows Sysmon with XML is auto-handled by most log agents to abstract the XML parsing away. However, Linux log agents do not account for this. While I don't think it's a huge deal I believe it would help the community more readily consume these logs if they supported other log formats outside of XML.

Examples:

  • JSON
  • key-value pairs (base pairs or a standard like LEF, LEEF, or CEF)

Regardless, in its current format, Sysmon for Linux is a huge blessing to the community regardless of the above. I'm just submitting this as a possible feature request.

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

Issue にはファイル、テスト、エントリーポイントが記載されていません。まず現在の XML ログ出力パスを特定し、次に要求されている形式のうち、どれを対象範囲に含めるかを判断してください: JSON または LEF、LEEF、CEF などの key-value 標準。選択した形式について、対象とする形式の範囲が合意され、出力動作が検証されていれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
c, json
領域
operating-systems
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
説明が足りない
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。