berthayes / cp-zeekLinks
Analyze Zeek IDS data with ksqlDB running on Confluent Platform via Docker on your laptop. Or spin up an arbitrary number of AWS hosts, each running Confluent Platform and ksqlDB for use in an instructor-led workshop.
☆11Updated 4 years ago
Alternatives and similar repositories for cp-zeek
Users that are interested in cp-zeek are comparing it to the libraries listed below
Sorting:
- ☆19Updated 3 years ago
- Geospatial UDFs for KSQL☆22Updated 4 years ago
- Kafka connector for Splunk☆97Updated 3 months ago
- A Workflow for Data Scientists to bring Jupyter Notebook Visualizations to Kibana Dashboards☆45Updated 2 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 months ago
- Sankey diagram for Kibana visualize.☆32Updated last year
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- RELK -- The Research Elastic Stack (Kafka, Beats, Zookeeper, Logstash, ElasticSearch, Kibana, Spark, & Jupyter -- All in Docker)☆26Updated 6 years ago
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆69Updated 5 months ago
- A Python library to help with some common threat hunting data analysis operations☆143Updated 2 years ago
- MonitoFi: Health & Performance Monitor for your Apache NiFi☆68Updated 2 years ago
- Bro scripts for the ROCK platform. http://rocknsm.io☆34Updated 2 years ago
- Dashboards and loader for ROCK NSM dashboards☆49Updated 2 years ago
- Open-source framework to detect outliers in Elasticsearch events☆208Updated 2 years ago
- ☆74Updated 4 years ago
- Zeek support for Community ID flow hashing.☆37Updated 2 years ago
- ☆15Updated 8 years ago
- ☆38Updated 6 years ago
- A Java library for handling TAXII Messages and invoking TAXII Services.☆20Updated 6 years ago
- Kibana Milestones Visualization☆90Updated 2 years ago
- Data Governance app for Splunk☆12Updated 2 years ago
- Apache Metron Workshop Lab materials and instructions.☆35Updated 6 years ago
- A pivot table plugin for Kibana 5☆24Updated 7 years ago
- ☆92Updated 2 years ago
- Splunk Alert Manager with advanced reporting on alerts, workflows (modify assignee, status, severity) and auto-resolve features☆81Updated 3 years ago
- Data validator agains Splunk Common Information Model (CIM)☆78Updated last year
- SIEM Logstash parsing for more than hundred technologies☆192Updated this week
- ☆225Updated last month
- Apache Metron☆60Updated 5 years ago
- This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆27Updated 4 years ago