I installed the critical-stack agent

I pulled the feeds and the master file was created successfully

But when I trying to test it , and connect to forbidden address , I’m not getting the log in the intel.log like I should

Actually there is no file “intel.log”

What am I missing ?

I was following this article



I can't read their article because it needs a log in. That being said -
assuming you follow steps similar to, especially the redef
Intel::read_files part, data should be read in by Bro and the intel.log
should get generated.

If it does not, check if you have a reporter.log that complains about
issues reading the file.