Anonymity94 / spl2dsl
Convert Splunk SPL to Elasticsearch DSL with pegjs
☆13Updated 2 years ago
Alternatives and similar repositories for spl2dsl:
Users that are interested in spl2dsl are comparing it to the libraries listed below
- Convert Splunk SPL to ClickHouse SQL with pegjs☆13Updated 2 years ago
- Mine patterns from logs☆27Updated 8 years ago
- ☆23Updated 4 years ago
- Elastic Search Processing Language☆49Updated 8 years ago
- Simple parser for Splunk Processing Language (SPL) written in Python.☆35Updated 6 years ago
- golang sliding or tumbling window stream-processing☆12Updated 4 years ago
- Bluekeep detection rule by using Apache Flink CEP (Complex Event Processing) Library and Markov Chain.☆9Updated 5 years ago
- Elasticsearch querying library☆20Updated 5 years ago
- flink-cep☆17Updated 6 years ago
- Apache Metron☆59Updated 4 years ago
- didiyun super-agent daemon☆59Updated 6 years ago
- Query.AI plugin for Kibana☆13Updated 5 years ago
- ES索引的维护脚本, 每天close delete reallocate optimize索引☆23Updated 5 years ago
- GO开发而成,用于NIDS HIDS 分析的规则引擎,使用WorkerPool 高性能检测,支持多字段 "和" "或" 检测, 支持频率检测☆76Updated last month
- Yara powered NIDS with high speed packet capture powered by PF_RING☆69Updated 10 months ago
- 类filebeat的轻量级日志采集工具☆69Updated 5 years ago
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆31Updated 4 years ago
- Analysis of HTTP traffic and detection of anomalous user behavior in allowed actions. UEBA system.☆22Updated 2 years ago
- 基于Strom的日志实时流量分析主动防御(CCFirewall)系统☆71Updated 7 years ago
- Parse Suricata rules☆12Updated last year
- 威胁检测规则集☆15Updated 5 years ago
- Open-source framework to detect outliers in Elasticsearch events☆208Updated last year
- d18n is a data desensitization tool for RDBMS.☆173Updated 2 years ago
- Quickly generate suricata rules for IOCs☆28Updated 3 years ago
- Collection of various open-source an commercial rulesets for NIDS (especially for Suricata and Snort)☆23Updated last year
- Configuring the Suricata IDS to detect DoS attacks by adding custom rule file.☆39Updated 4 years ago
- ☆16Updated 8 years ago
- A CEP library to run Siddhi within Apache Flink™ Streaming Application (Not maintained)☆244Updated last year
- Elkeid HUB is a rule/event processing engine maintained by the Elkeid Team that supports streaming/offline (not yet supported by the comm…☆94Updated last year
- Parser for Splunk's Search Processing Language (SPL) syntax highlighting☆19Updated 5 years ago