berthayes / cp-zeekLinks
Analyze Zeek IDS data with ksqlDB running on Confluent Platform via Docker on your laptop. Or spin up an arbitrary number of AWS hosts, each running Confluent Platform and ksqlDB for use in an instructor-led workshop.
☆11Updated 3 years ago
Alternatives and similar repositories for cp-zeek
Users that are interested in cp-zeek are comparing it to the libraries listed below
Sorting:
- ☆19Updated 3 years ago
- A Workflow for Data Scientists to bring Jupyter Notebook Visualizations to Kibana Dashboards☆45Updated 2 years ago
- Kafka connector for Splunk☆94Updated 11 months ago
- Geospatial UDFs for KSQL☆22Updated 3 years ago
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆69Updated 8 years ago
- Sankey diagram for Kibana visualize.☆31Updated 8 months ago
- ☆15Updated 8 years ago
- A Python library to help with some common threat hunting data analysis operations☆143Updated 2 years ago
- Open-source framework to detect outliers in Elasticsearch events☆209Updated 2 years ago
- Confluent s2s Demo☆10Updated 2 years ago
- Kibana Milestones Visualization☆90Updated 2 years ago
- ☆38Updated 5 years ago
- SIEM Logstash parsing for more than hundred technologies☆187Updated last month
- Contains Logstash related content including tons of Logstash configurations☆254Updated 3 years ago
- Data validator agains Splunk Common Information Model (CIM)☆76Updated last year
- Bro scripts for the ROCK platform. http://rocknsm.io☆34Updated 2 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last month
- A pivot table plugin for Kibana 5☆24Updated 6 years ago
- Splunk Alert Manager with advanced reporting on alerts, workflows (modify assignee, status, severity) and auto-resolve features☆81Updated 3 years ago
- A Java library for handling TAXII Messages and invoking TAXII Services.☆20Updated 6 years ago
- Dashboards and loader for ROCK NSM dashboards☆49Updated 2 years ago
- User interface for OpenSOC☆100Updated 10 years ago
- Firepit - STIX Columnar Storage☆16Updated last year
- Zeek support for Community ID flow hashing.☆36Updated 2 years ago
- The Elastic Security Research team produces public-facing content, in the way of summary blogs, detailed releases, and artifacts; articul…☆9Updated 3 years ago
- ☆221Updated last year
- This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆27Updated 4 years ago
- Additional convenience processors not found in core Apache NiFi☆94Updated 3 years ago
- Data Governance app for Splunk☆12Updated last year