Skip to main content
Question

DNS Header Flag fields that are boolean, can I convert this to ECS by just having one object

  • March 11, 2025
  • 30 replies
  • 109 views

Show first post

30 replies

Jon Rust
Forum|alt.badge.img
  • Employee
  • March 11, 2025

this is a good place to start: https://sandbox.cribl.io/course/expressions


Is this particular technique covered in that course?


Jon Rust
Forum|alt.badge.img
  • Employee
  • March 11, 2025

the really great thing about Cribl using JS for its processing language is it's so easy to code by ~google~ duckduckgo


Jon Rust
Forum|alt.badge.img
  • Employee
  • March 11, 2025

no, it's more generic. will help with the basics


Yeah, I was more looking for keywords of how to ~google~ presearch the particular technique.