Anonymity94 / spl2dsl
Convert Splunk SPL to Elasticsearch DSL with pegjs
☆13Updated 3 years ago
Alternatives and similar repositories for spl2dsl:
Users that are interested in spl2dsl are comparing it to the libraries listed below
- Mine patterns from logs☆27Updated 8 years ago
- Convert Splunk SPL to ClickHouse SQL with pegjs☆13Updated 2 years ago
- Elastic Search Processing Language☆49Updated 8 years ago
- ☆23Updated 4 years ago
- ES索引的维护脚本, 每天close delete reallocate optimize索引☆23Updated 6 years ago
- A fault-tolerant events/alerts correlation engine☆25Updated 6 years ago
- GO开发而成,用于NIDS HIDS 分析的规则引擎,使用WorkerPool 高性能检测,支持多字段 "和" "或" 检测, 支持频率检测☆77Updated 2 months ago
- Query.AI plugin for Kibana☆13Updated 5 years ago
- Apache Metron☆59Updated 4 years ago
- Elkeid HUB is a rule/event processing engine maintained by the Elkeid Team that supports streaming/offline (not yet supported by the comm…☆95Updated last year
- Simple parser for Splunk Processing Language (SPL) written in Python.☆35Updated 6 years ago
- 🚀 A High-performance Gateway Designed for Search Scenarios. Good friend of Elasticsearch / Opensearch / Easysearch.☆56Updated this week
- 类filebeat的轻量级日志采集工具☆69Updated 5 years ago
- didiyun super-agent daemon☆59Updated 6 years ago
- Analysis of HTTP traffic and detection of anomalous user behavior in allowed actions. UEBA system.☆22Updated 2 years ago
- Google V8 with OpenRASP builtins☆57Updated 4 years ago
- nebula 文档, gitbook版☆73Updated 5 years ago
- ☆28Updated last year
- golang sliding or tumbling window stream-processing☆12Updated 4 years ago
- A Zeek log writer plugin that publishes to Kafka.☆46Updated 3 months ago
- Suricata安装部署&丢包优化&性能调优&规则调整&Pfring设置☆141Updated 5 years ago
- Open Source Security Information and event Management☆91Updated 9 years ago
- Open-source framework to detect outliers in Elasticsearch events☆209Updated last year
- Data exporter of Nebula Graph☆18Updated 3 months ago
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆31Updated 5 years ago
- Bluekeep detection rule by using Apache Flink CEP (Complex Event Processing) Library and Markov Chain.☆9Updated 5 years ago
- A proxy behind nginx while before kibana (4.x, 5.x) to provide data isolation for different users☆24Updated 5 years ago
- jkstack agent统一管理服务☆16Updated 11 months ago
- teler Resource Collections☆36Updated this week
- ☆16Updated 8 years ago