berthayes / cp-zeekLinks
Analyze Zeek IDS data with ksqlDB running on Confluent Platform via Docker on your laptop.  Or spin up an arbitrary number of AWS hosts, each running Confluent Platform and ksqlDB for use in an instructor-led workshop.
☆11Updated 4 years ago
Alternatives and similar repositories for cp-zeek
Users that are interested in cp-zeek are comparing it to the libraries listed below
Sorting:
- ☆19Updated 3 years ago
 - Kafka connector for Splunk☆96Updated last month
 - Geospatial UDFs for KSQL☆22Updated 4 years ago
 - A Workflow for Data Scientists to bring Jupyter Notebook Visualizations to Kibana Dashboards☆45Updated 2 years ago
 - Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last month
 - Data Governance app for Splunk☆12Updated 2 years ago
 - SIEM Logstash parsing for more than hundred technologies☆188Updated 2 weeks ago
 - Zeek support for Community ID flow hashing.☆37Updated 2 years ago
 - Data validator agains Splunk Common Information Model (CIM)☆76Updated last year
 - Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
 - Kibana Milestones Visualization☆90Updated 2 years ago
 - Bro scripts for the ROCK platform. http://rocknsm.io☆34Updated 2 years ago
 - A Python library to help with some common threat hunting data analysis operations☆143Updated 2 years ago
 - RELK -- The Research Elastic Stack (Kafka, Beats, Zookeeper, Logstash, ElasticSearch, Kibana, Spark, & Jupyter -- All in Docker)☆26Updated 5 years ago
 - A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆69Updated 2 months ago
 - Apache Metron Workshop Lab materials and instructions.☆35Updated 5 years ago
 - Open-source framework to detect outliers in Elasticsearch events☆209Updated 2 years ago
 - Sankey diagram for Kibana visualize.☆32Updated 10 months ago
 - ☆15Updated 8 years ago
 - Dashboards and loader for ROCK NSM dashboards☆49Updated 2 years ago
 - Apache Metron☆60Updated 5 years ago
 - A selection of Canvas workpad examples☆87Updated 4 years ago
 - ☆224Updated 2 years ago
 - ☆38Updated 6 years ago
 - Splunk Alert Manager with advanced reporting on alerts, workflows (modify assignee, status, severity) and auto-resolve features☆81Updated 3 years ago
 - A Java library for handling TAXII Messages and invoking TAXII Services.☆20Updated 6 years ago
 - ☆74Updated 3 years ago
 - A machine learning plugin in Open Distro for real time anomaly detection on streaming data.☆80Updated 3 years ago
 - Kafka Connect connector for receiving data and writing data to Splunk.☆25Updated 7 years ago
 - This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆27Updated 4 years ago