How To Identify Incoming Data As A Custom Source Type

Posted by sysop on 12 September 2012 | 3 Comments

Tags: , , , , , ,

Overview

Honeycomb Lexicon comes with a large set of knowledge of popular data types and sources.

For data from sources that are unique to your organization or other unrecognized sources, Lexicon still stores and indexes the data, marking it as sourcetype ‘generic’.

This How To article describes the steps to mark this data to any sourcetype you like.

For example, if you have data in log files generated from a custom Web Server Application, the steps below will show you how to tag this data as a ‘webapp’ source type.

3 comments | Read the full post

Palo Alto Next Generation App!

Posted by Haydn Wall on 16 April 2012 | 0 Comments

Tags: , ,

Honeycomb Palo Alto Next Generation App!

0 comments | Read the full post

Honeycomb Lexicon Pre-Installation Guidelines

Posted by sysop on 15 March 2012 | 0 Comments

Tags: , , , , ,

Overview

This post outlines some useful guidelines and best practices prior to installing the Honeycomb Lexicon® and mesh® services.

0 comments | Read the full post

Make the Most of Your Palo Alto Firewall Data

Posted by sysop on 5 March 2012 | 0 Comments

Tags: , , , , , ,

Intro

This post walks through the steps to integrate Palo Alto firewall data into Honeycomb Lexicon. Palo Alto next-generation firewalls provide a vast wealth of protection and visibility right through the network stack. Integrating Palo Alto firewall data into Honeycomb Lexicon leverages this data, and allows you to easily visualize data patterns, as well as correlate its data with the rest of your network.

0 comments | Read the full post

Gathering VMWare Host Data

Posted by sysop on 5 March 2012 | 0 Comments

Tags: , , , , ,

Intro

Today's post talks about the configuration and setup for sending and receiving VMWare ESX host logs and system events into Honeycomb Lexicon.

0 comments | Read the full post