This is an update for logstash and dashboard published in January for Didier’s tcp-honeypot.py honeypot script. The parser has been updated to follow the Elastic Common Schema (ECE) format, parsing more information from the honeypot logs that include revised and additional dashboards.
Article Link: https://isc.sans.edu/diary/rss/26288