airbus-cyber / graylog-plugin-alert-wizard
Alert Wizard plugin for Graylog to manage the alert rules
☆48Updated 2 weeks ago
Alternatives and similar repositories for graylog-plugin-alert-wizard:
Users that are interested in graylog-plugin-alert-wizard are comparing it to the libraries listed below
- Alert notification plugin for Graylog to generate log messages from alerts☆25Updated 2 weeks ago
- Alert condition plugin for Graylog to perform correlation☆25Updated 4 months ago
- Alert condition plugin for Graylog to perform aggregation☆20Updated 2 years ago
- Sysmon and wazuh integration with Sigma sysmon rules [updated]☆65Updated 3 years ago
- Fortinet products logs to Elasticsearch☆98Updated 8 months ago
- Wazuh - Splunk App☆53Updated 7 months ago
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆27Updated 4 years ago
- Convert Sigma rules to Wazuh rules☆64Updated last year
- Kibana 7 Templates for Suricata IDPS Threat Hunting☆40Updated 2 years ago
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19Updated 3 years ago
- Simple integration script for 3rd party systems such as SIEMs. Offers command line, file or syslog output in CEF, JSON or key-value pair …☆131Updated last year
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆71Updated last year
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆22Updated 3 months ago
- Elastic Beat for fetching and shipping Office 365 audit events☆67Updated 4 years ago
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- SIEM Logstash parsing for more than hundred technologies☆184Updated 2 weeks ago
- ☆58Updated last year
- Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases☆153Updated last year
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated last week
- ☆35Updated last year
- ☆23Updated 5 years ago
- Leverage Sophos Central API☆27Updated last year
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last week
- A curated list of awesome things related to TheHive & Cortex☆178Updated 3 years ago
- ☆31Updated 3 years ago
- Unofficial third-party scripts, playbooks, and content for IBM QRadar & QRadar Community Edition.☆82Updated last month
- OwlH Master API☆24Updated last week
- Configuration for a Palo Alto Networks fed ELK Stack with Visualizations☆73Updated 6 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables