corelight / ecs-logstash-mappingsLinks
Mapping Corelight or Zeek data to Elastic Common Schema logs
☆12Updated 2 months ago
Alternatives and similar repositories for ecs-logstash-mappings
Users that are interested in ecs-logstash-mappings are comparing it to the libraries listed below
Sorting:
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- SIEM Logstash parsing for more than hundred technologies☆188Updated this week
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆189Updated last year
- Plugins for Wazuh Dashboard☆486Updated this week
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 weeks ago
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆24Updated 9 months ago
- A Zeek log writer plugin that publishes to Kafka.☆51Updated 3 months ago
- Wazuh - Ruleset☆491Updated last year
- Kafka connector for Splunk☆97Updated 2 months ago
- Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailo…☆91Updated this week
- Fortinet products logs to Elasticsearch☆98Updated last week
- Splunk Connect for Syslog☆171Updated last week
- Open source endpoint agent providing host information to Zeek. [v2]☆88Updated 3 weeks ago
- STIX 2.x Java Library☆30Updated 3 years ago
- A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by D…☆461Updated last year
- CEF codec for Logstash☆22Updated last year
- Mapping the MITRE ATT&CK Matrix with Osquery☆802Updated 2 years ago
- The tool for updating your Suricata rules.☆282Updated 3 weeks ago
- Contains Logstash related content including tons of Logstash configurations☆254Updated 4 years ago
- 🔐 Manage your internal users, roles, access control, and audit logs from OpenSearch Dashboards☆86Updated 2 weeks ago
- ☆12Updated 2 months ago
- ☆26Updated last week
- Repository for Cribl Helm Charts☆48Updated last month
- Documentation of Cortex☆175Updated 2 years ago
- Splunk Docker GitHub Repository☆516Updated this week
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆69Updated 3 months ago
- Splunk App for Cribl Stream and Edge Observability☆25Updated 4 months ago
- Beat to get SNMP data☆24Updated 7 years ago
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆323Updated last year
- A repository for using osquery for incident detection and response☆867Updated 2 months ago