What is the difference between network telemetry and network alert logs?

Sound the Alarm: Detection and Response | Weekly challenge 4 Quiz | 

What is the difference between network telemetry and network alert logs?

  • Network telemetry is the output of a signature; network alert logs contain details about malicious activity.
  • Both provide information that is relevant for security analysts, but network alert logs contain network connection details.
  • Network telemetry contains information about network traffic flows; network alert logs are the output of a signature.
  • Network telemetry is output in EVE JSON format; network alert logs are output in HTML.


Leave a Comment