I cannot interact with the eve_archived.json file. It is in the directory:
But when I run the command ‘less eve_archived.json’ I get nothing but a blank screen:
I can access the eve.json file:
I’m unable to run the subsequent commands as well:
cat eve_archived.json | jq -c 'select(.event_type == "alert")'
cat eve_archived.json | jq -c 'select(.event_type == "tls")'
I am using a Windows 10 machine and Putty. Do I need to install EveBox and jq for this to work?
Original post by bjadamsjr
Please always mention the exact lab when posting.
You need to install nothing.
A new file with a similar name has been created by the system.
The filename is now eve_archived.json.1
Original reply by Dimitrios