π΅Fixit
Fixit
INTRO
Fix event boundaries

Questions part 1
What is the full path of the FIXIT app directory?

What Stanza will we use to define Event Boundary in this multi-line Event case?
In the inputs.conf, what is the full path of the network-logs script?

What regex pattern will help us define the Event's start?
Extract Custom Fields
Questions part 2
What is the captured domain?

How many countries are captured in the logs?
How many departments are captured in the logs?
How many usernames are captured in the logs?
How many source IPs are captured in the logs?
Which configuration files were used to fix our problem? [Alphabetic order: File1, file2, file3]
What are the TOP two countries the user Robert tried to access the domain from? [Answer in comma-separated and in Alphabetic Order][Format: Country1, Country2]

Which user accessed the secret-document.pdf on the website?

Conclusion
Last updated