LimaCharlie
Backstory supports ingesting LimaCharlie telemetry in order to visualize what is happening on the hosts themselves. Backstory requires only a very simple syslog configuration to a syslog listener setup by CYDERES.
Backstory Data Types
- EDR
- DNS
Configuration
- In the LimaCharlie management portal, select Outputs.
- At the top right, select the
+
symbol to add a new output. - Name the output "CYDERES".
-
Select the "syslog" module.
-
In the "Destination Host" field, enter in the syslog endpoint information provided by CYDERES.
- Select the "Use SSL" slider option.
- Select the "No Headers" slider option
- Select "Create".