I was recently asked how I can quickly and efficiently analyze Kippo results. The secret is generating an additional log with Kippo, and inputting the results into Splunk. Since this data could be useful for researchers everywhere, I've decided to type up a quick tutorial.
In order to have Kippo generate the needed log, you need to create a batch file or shell script designed to generate the log.
For Windows, your batch file will look something like this:
twistd.py -y kippo.tac >> "Kippo.log"
For non-Windows, logging is already enabled by default, and will be saved to:
log/kippo.log
Once Kippo is generating logs, you can either upload these logs to Splunk manually, or use Splunk's Universal Forwarder to upload automatically.
