Anonymity94 / spl2dsl
Convert Splunk SPL to Elasticsearch DSL with pegjs
☆13Updated 2 years ago
Alternatives and similar repositories for spl2dsl:
Users that are interested in spl2dsl are comparing it to the libraries listed below
- Convert Splunk SPL to ClickHouse SQL with pegjs☆13Updated 2 years ago
- Mine patterns from logs☆27Updated 8 years ago
- ☆23Updated 4 years ago
- Elastic Search Processing Language☆49Updated 8 years ago
- A fault-tolerant events/alerts correlation engine☆25Updated 5 years ago
- Elasticsearch querying library☆20Updated 5 years ago
- Apache Metron☆59Updated 4 years ago
- SysFlow documentation and issues tracker☆46Updated 3 months ago
- GO开发而成,用于NIDS HIDS 分析的规则引擎,使用WorkerPool 高性能检测,支持多字段 "和" "或" 检测, 支持频率检测☆77Updated 3 years ago
- Simple parser for Splunk Processing Language (SPL) written in Python.☆35Updated 6 years ago
- ES索引的维护脚本, 每天close delete reallocate optimize索引☆23Updated 5 years ago
- Elkeid HUB is a rule/event processing engine maintained by the Elkeid Team that supports streaming/offline (not yet supported by the comm…☆93Updated last year
- Analysis of HTTP traffic and detection of anomalous user behavior in allowed actions. UEBA system.☆21Updated last year
- Elastic Beats Output to Apache Pulsar☆56Updated 3 months ago
- ☆12Updated last year
- A Zeek log writer plugin that publishes to Kafka.☆46Updated 2 weeks ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆67Updated 8 months ago
- 🚀 A High-performance Gateway Designed for Search Scenarios. Good friend of Elasticsearch / Opensearch / Easysearch.☆39Updated this week
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆32Updated 4 years ago
- Collection of various open-source an commercial rulesets for NIDS (especially for Suricata and Snort)☆23Updated last year
- 通过Linux netlink NETLINK_CONNECTOR 协议实时进行监控本机进程情况。☆13Updated 5 years ago
- jkstack agent统一管理服务☆15Updated 8 months ago
- Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)☆78Updated 3 months ago
- Meer is a "spooler" for Suricata / Sagan.☆28Updated last year
- ☆21Updated 7 years ago
- Google V8 with OpenRASP builtins☆56Updated 3 years ago
- provides a Suricata Eve output for Kafka with Suricate Eve plugin☆14Updated 3 years ago
- Unified SQL Analytics Engine Based on SparkSQL☆210Updated 2 years ago
- ☆24Updated last year