corelight / ecs-logstash-mappingsLinks
Mapping Corelight or Zeek data to Elastic Common Schema logs
☆12Updated 3 months ago
Alternatives and similar repositories for ecs-logstash-mappings
Users that are interested in ecs-logstash-mappings are comparing it to the libraries listed below
Sorting:
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- SIEM Logstash parsing for more than hundred technologies☆189Updated last week
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆24Updated 10 months ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last month
- Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailo…☆91Updated this week
- A Zeek log writer plugin that publishes to Kafka.☆51Updated 3 months ago
- Plugins for Wazuh Dashboard☆488Updated this week
- Fortinet products logs to Elasticsearch☆101Updated last week
- Wazuh - Ruleset☆492Updated last year
- Process, reduce, and transform Palo Alto Networks Firewall logs.☆18Updated 3 months ago
- Beat to get SNMP data☆24Updated 7 years ago
- Fast and efficient osquery management☆475Updated 2 weeks ago
- ☆26Updated 2 weeks ago
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆190Updated last year
- Open source endpoint agent providing host information to Zeek. [v2]☆90Updated 2 weeks ago
- Command line tool used for generating events corpus dynamically given a specific integration☆23Updated 10 months ago
- Simple integration script for 3rd party systems such as SIEMs. Offers command line, file or syslog output in CEF, JSON or key-value pair …☆137Updated 2 years ago
- Splunk App for Cribl Stream and Edge Observability☆25Updated 4 months ago
- This repo contains example of raw event examples and possible translations to the OCSF schema.☆50Updated 4 months ago
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆447Updated this week
- Contains Logstash related content including tons of Logstash configurations☆254Updated 4 years ago
- Splunk Connect for Syslog☆171Updated this week
- Alert Wizard plugin for Graylog to manage the alert rules☆49Updated this week
- The tool for updating your Suricata rules.☆284Updated last month
- ElastAlert that exposes REST API's for manipulating rules and alerts☆48Updated 2 weeks ago
- Documentation of Cortex☆175Updated 2 years ago
- Configuration for a Palo Alto Networks fed ELK Stack with Visualizations☆75Updated 6 years ago
- App examples for Splunk Enterprise☆150Updated 2 months ago
- DynamiteNSM is a free Network Security Monitor developed by Dynamite Analytics to enable network visibility and advanced cyber threat det…☆171Updated 2 years ago
- Repository for Cribl Helm Charts☆48Updated 3 weeks ago