|
@@ -18,4 +18,9 @@ Logging is horrible. Clamd by default writes to a logfile, but doesn't apparent
|
|
|
log when a scan actually runs or what its results were, unless that scan finds
|
|
|
something.
|
|
|
|
|
|
+See salt/fileroots/internal_splunk_forwarder/files/TA-clamav/default/inputs.conf for the locations splunk is looking for.
|
|
|
+
|
|
|
+## Exceptions and False Positives
|
|
|
+
|
|
|
+See also: https://github.xdr.accenturefederalcyber.com/mdr-engineering/msoc-infrastructure/wiki/AV-Exceptions
|
|
|
|