https://github.com/osquery/osquery logo
s

sundsta

09/02/2020, 10:52 PM
I would be interested in topics along the lines of best practices for normalizing data from mac+win+linux endpoints so that generic alerts can be created for them.
s

seph

09/02/2020, 11:25 PM
I don't think there's a simple answer. Depends on the data. And in some cases the platforms cannot easily normalize.
s

sundsta

09/02/2020, 11:29 PM
Agreed 🙂 That’s why I’m interested in others’ methods
5 Views