PolitoInc / DNS-ELK
Experimental DNS logs pipeline based on Pi-hole dnsmasq logs, ELK stack, and Filebeat. Sample configs included.
☆30Updated last year
Related projects ⓘ
Alternatives and complementary repositories for DNS-ELK
- Stream Lookup function for GrayLog2 Pipeline Processor☆14Updated 3 years ago
- Simple block lists hub for PAN-OS DBL feature☆35Updated 5 years ago
- Dashboards and loader for ROCK NSM dashboards☆48Updated last year
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19Updated 3 years ago
- Logstash Configuration for Linux Logs (Authentication, Apache, Mail)☆92Updated 5 years ago
- Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases☆150Updated 8 months ago
- ☆23Updated 5 years ago
- Files from my Storm Center Articles☆17Updated 10 months ago
- Configuration for a Palo Alto Networks fed ELK Stack with Visualizations☆74Updated 5 years ago
- Example configuration files for Logstash☆45Updated 5 years ago
- WebUI of MineMeld☆43Updated last year
- How to send structured Snort IDS alert logs into Graylog☆27Updated last year
- bro on debian with elasticsearch support☆24Updated 7 years ago
- ioc2rpz is a place where threat intelligence meets DNS.☆106Updated 2 months ago
- Ansible playbook for installing MineMeld on Linux☆48Updated 3 years ago
- MineMeld nodes for MISP☆18Updated 10 months ago
- Bro script package to create JSON formatted logs to stream into data analysis systems.☆28Updated 11 months ago
- brostash: Linux distribution based on Debian and focusing on network security events collection☆34Updated 4 years ago
- Zeek support for Community ID flow hashing.☆34Updated last year
- Fetches multiple blacklists, formats, outputs to text file for use with Palo Alto firewalls (possibly others).☆13Updated 9 years ago
- SIAC is an enterprise SIEM built on open-source technology.☆113Updated 6 years ago
- Push "BAD" IPs/Networks into QRadar's "Remote Networks", tag them properly, and use them!☆18Updated 11 years ago
- Elastic Beat for fetching and shipping Office 365 audit events☆66Updated 4 years ago
- ansible role to setup MISP, Malware Information Sharing Platform & Threat Sharing☆52Updated 2 weeks ago
- Logstash Configs and Kibana Dashboards for F5 LTM & ASM☆16Updated 7 years ago
- PANW Firewall Visualisations using Elastic Stack☆90Updated last year
- Kibana 6 Templates for Suricata IDPS Threat Hunting☆25Updated 5 years ago
- Cyber Defence Monitoring Course Suite :: Suricata, Arkime (and others in the past)☆100Updated 5 months ago