LimaCharlie Log In
v1
v1
Deprecated
v2
Contents
x
Getting Started
Telemetry
Detection and Response
Platform Management
Outputs
Add-Ons
FAQ
Powered by
Telemetry
7 Articles
in this category
Contributors
+ 1
Share this
Print
Share
Dark
Light
Contents
Telemetry
7 Articles
in this category
+ 1
Written by
Matt Bromiley
,
Whitney Champion
,
Maxime Lamothe Brassard
and 1 others
Share
Dark
Light
Creating a Webhook Adapter
LimaCharlie supports webhooks as a telemetry ingestion method. Webhooks are technically cloud Adapters , as they cannot be deployed on-prem or through the downloadable adapter binary. Webhook adapters are created by enabling a webhook through the...
Written by
Matt Bromiley
Updated on : 26 Aug 2023
Ingesting Google Cloud Logs
With LimaCharlie, you can easily ingest Google Cloud logs for further processing and automation. This article covers the following high-level steps of shipping logs from GCP into LimaCharlie: Create a Log Sink to Pubsub in GCP Create a Subscri...
Written by
Matt Bromiley
Updated on : 11 Aug 2023
Ingesting Linux Audit Logs
One data source of common interest on Linux systems is the audit.log file. By default, this file stores entries from the Audit system, which contains information about logins, privilege escalations, and other account-related events. You can find m...
Written by
Matt Bromiley
Updated on : 27 Jul 2023
Ingesting Sysmon Event Logs
Sysmon can be a valuable addition to any defender's toolkit, given it's verbosity and generous log data. It's worth noting that LimaCharlie's native EDR capabilities mirror much of the same telemetry. However, Sysmon and LimaCharlie can be combined ...
Written by
Matt Bromiley
,
Whitney Champion
Updated on : 04 Sep 2024
Ingesting Telemetry from Cloud-Based External Sources
LimaCharlie allows for ingestion of logs or telemetry from any external source in real-time. It includes built-in parsing for popular formats, with the option to define your own for custom sources. There are two ways to ingest logs or telemetry fr...
Written by
Matt Bromiley
Updated on : 10 Jul 2023
Ingesting Windows Event Logs
You can enable real-time Windows Event Log (WEL) ingestion using the LimaCharlie EDR Sensor. First, navigate to the Exfil Control section of LimaCharlie and ensure that WEL events are enabled for your Windows rules. Next, navigate to the ...
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Eric Capuano
Updated on : 18 Jan 2024
Ingesting MacOS Unified Logs
You can enable real-time MacOS Unified Logs (MUL) ingestion using the LimaCharlie EDR Sensor. First, navigate to the Exfil Control section of LimaCharlie and ensure that MUL events are enabled for your Windows rules. Next, navigate to the ...
Written by
Maxime Lamothe Brassard
Updated on : 08 Jul 2024