cameling / logminer
Mine patterns from logs
☆27Updated 7 years ago
Related projects ⓘ
Alternatives and complementary repositories for logminer
- Simple parser for Splunk Processing Language (SPL) written in Python.☆35Updated 6 years ago
- User anomaly detector based on logs generated by Osquery framework and machine learning to process those logs.☆33Updated 7 years ago
- Elastic Search Processing Language☆49Updated 8 years ago
- Convert Splunk SPL to Elasticsearch DSL with pegjs☆13Updated 2 years ago
- Network timing evaluation used to detect beacons, works with argus flow as the source☆19Updated 8 years ago
- Query.AI plugin for Kibana☆13Updated 5 years ago
- Open-source framework to detect outliers in Elasticsearch events☆205Updated last year
- A Zeek package that detects Zoom logins and meeting joins☆11Updated 4 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago
- User and Entity Behavior Analytics by deep learning☆100Updated 3 years ago
- Total Anomaly Detection System for software logs and traces☆9Updated 8 years ago
- pyJARM is a library for doing JARM fingerprinting using python☆50Updated 3 years ago
- Parser for Splunk's Search Processing Language (SPL) syntax highlighting☆17Updated 4 years ago
- Advanced Persistent Threat Detection Using Network Analysis☆22Updated 5 years ago
- ES索引的维护脚本, 每天close delete reallocate optimize索引☆23Updated 5 years ago
- Apache Metron☆59Updated 4 years ago
- Utility for parsing Bro log files into CSV or JSON format☆41Updated last year
- User interface for OpenSOC☆100Updated 9 years ago
- Open Source ETL designed for and dedicated to Log processing and transformation☆68Updated last year
- Elasticsearch querying library☆20Updated 5 years ago
- Anomaly detection for streaming time series, featuring automated model selection.☆203Updated 8 months ago
- • Packet capture (PCAP) file analysis to analyze traffic sent by malicious IP address.☆12Updated 9 years ago
- Very basic CLI SIEM (Security Information and Event Management system).☆35Updated 6 years ago
- Anomaly detection and monitoring software☆20Updated 6 years ago
- Open Source Security Information and event Management☆81Updated 9 years ago
- Script to create MITRE ATT&CK Navigator layers from the annotated detection rules in Elastic Security (Kibana).☆20Updated last year
- A repository for OSSEC rules and decoders☆51Updated last year
- ☆29Updated this week
- Graph database version of the CVE database☆24Updated last year
- Generate JSON force-directed/ node graph data from MITRE's ATTACK framework and visualize it interactively☆22Updated 3 years ago