corelight / ecs-logstash-mappingsLinks
Mapping Corelight or Zeek data to Elastic Common Schema logs
☆13Updated last month
Alternatives and similar repositories for ecs-logstash-mappings
Users that are interested in ecs-logstash-mappings are comparing it to the libraries listed below
Sorting:
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- SIEM Logstash parsing for more than hundred technologies☆188Updated last week
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆187Updated last year
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last month
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆23Updated 8 months ago
- A Zeek log writer plugin that publishes to Kafka.☆51Updated 2 months ago
- Splunk App for Cribl Stream and Edge Observability☆25Updated 3 months ago
- The tool for updating your Suricata rules.☆280Updated 3 weeks ago
- Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailo…☆91Updated this week
- This repo contains example of raw event examples and possible translations to the OCSF schema.☆48Updated 2 months ago
- Wazuh - Ruleset☆484Updated last year
- App examples for Splunk Enterprise☆149Updated last month
- Splunk Connect for Syslog☆167Updated last week
- TrackMe - Data tracking system for Splunk admins☆50Updated 2 years ago
- Kafka connector for Splunk☆97Updated last month
- CEF codec for Logstash☆22Updated last year
- Atlasian JIRA add-on for Splunk alert actions☆13Updated 3 weeks ago
- Open source endpoint agent providing host information to Zeek. [v2]☆86Updated last month
- Beat to get SNMP data☆24Updated 7 years ago
- ElastAlert that exposes REST API's for manipulating rules and alerts☆46Updated last week
- Documentation of Cortex☆174Updated 2 years ago
- Plugins for Wazuh Dashboard☆488Updated last week
- This is a python script that can be run on each Splunk Indexer for the purpose of exporting historical bucket data (raw events + metadata…☆11Updated last year
- Contains Logstash related content including tons of Logstash configurations☆254Updated 4 years ago
- Splunk Admins application to assist with troubleshooting Splunk enterprise installations☆97Updated this week
- Splunk App for Data Science and Deep Learning - container images repository☆59Updated last month
- Ansible framework providing a fast and simple way to spin up complex Splunk environments.☆131Updated last month
- Universal Configuration Console (UCC) is a developer toolkit that simplifies creating Technology Add-ons. UCC provides a comprehensive so…☆76Updated this week
- Built-in Panther detection rules and policies☆421Updated this week
- Docker files for building Zeek.☆87Updated 2 years ago