corelight / ecs-logstash-mappings
Mapping Corelight or Zeek data to Elastic Common Schema logs
☆12Updated 3 months ago
Alternatives and similar repositories for ecs-logstash-mappings:
Users that are interested in ecs-logstash-mappings are comparing it to the libraries listed below
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 months ago
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 2 years ago
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆22Updated 2 years ago
- SIEM Logstash parsing for more than hundred technologies☆182Updated this week
- A Zeek log writer plugin that publishes to Kafka.☆46Updated 3 weeks ago
- App examples for Splunk Enterprise☆128Updated 5 months ago
- Splunk App for Linux Auditd☆57Updated 3 years ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- Open source endpoint agent providing host information to Zeek. [v2]☆72Updated 3 months ago
- Splunk App for Cribl Stream and Edge Observability☆23Updated last month
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆67Updated 7 years ago
- Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, S…☆16Updated 3 years ago
- Bro script package to create JSON formatted logs to stream into data analysis systems.☆28Updated last year
- ☆17Updated last month
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆174Updated 4 months ago
- Docker files for building Zeek.☆86Updated last year
- Phantom Apps Repo☆82Updated 3 years ago
- Splunk App for Data Science and Deep Learning - container images repository☆50Updated 3 weeks ago
- Cisco eStreamer client☆25Updated 2 years ago
- OASIS TC Open Repository: TAXII 2 Server Library Written in Python☆125Updated 9 months ago
- Suricata Extreme Performance Tuning guide - Mark II☆115Updated 6 years ago
- This repo contains example of raw event examples and possible translations to the OCSF schema.☆35Updated this week
- Splunk Admins application to assist with troubleshooting Splunk enterprise installations☆93Updated this week
- Splunk Content Control Tool☆96Updated this week
- Plugin providing native AF_Packet support for Zeek.☆34Updated 9 months ago
- Documentation of Cortex☆171Updated last year
- TAXII client implementation from EclecticIQ☆98Updated 3 years ago
- OASIS TC Open Repository: Validator for STIX 2.0 JSON normative requirements and best practices☆51Updated last month
- Zeek Training Materials/Products☆37Updated this week
- Beat to get SNMP data☆24Updated 6 years ago