[tac_plus] Anyway to format the .acct file or have it log to syslog?

Alex D. listensammler at gmx.de
Wed Aug 22 19:48:03 UTC 2018


Hi Matt,
a possible solution would be logstash (see 
https://www.elastic.co/guide/en/logstash/current/introduction.html). You 
could use "file" input plugin, if needed do some filtering, and 
afterward you send it to your SIEM with the "syslog" output plugin.
Regards,
Alex



More information about the tac_plus mailing list