corelight / ecs-logstash-mappingsLinks
Mapping Corelight or Zeek data to Elastic Common Schema logs
☆12Updated last month
Alternatives and similar repositories for ecs-logstash-mappings
Users that are interested in ecs-logstash-mappings are comparing it to the libraries listed below
Sorting:
- SIEM Logstash parsing for more than hundred technologies☆193Updated 2 weeks ago
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- Plugins for Wazuh Dashboard☆495Updated this week
- Splunk Connect for Syslog☆171Updated this week
- A Zeek log writer plugin that publishes to Kafka.☆52Updated 5 months ago
- Fortinet products logs to Elasticsearch☆102Updated last week
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 3 months ago
- Splunk App for Cribl Stream and Edge Observability☆26Updated 6 months ago
- Wazuh - Ruleset☆502Updated last year
- Configuration for a Palo Alto Networks fed ELK Stack with Visualizations☆75Updated 6 years ago
- Beat to get SNMP data☆24Updated 7 years ago
- Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailo…☆95Updated this week
- ☆26Updated 2 weeks ago
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆24Updated last year
- ElastAlert that exposes REST API's for manipulating rules and alerts☆49Updated last week
- App examples for Splunk Enterprise☆151Updated last week
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆452Updated last week
- The Fleet server allows managing a fleet of Elastic Agents.☆107Updated this week
- ☆14Updated 2 weeks ago
- Splunk App for Data Science and Deep Learning - container images repository☆63Updated 2 months ago
- The tool for updating your Suricata rules.☆289Updated 3 months ago
- Kafka connector for Splunk☆97Updated 4 months ago
- Universal Configuration Console (UCC) is a developer toolkit that simplifies creating Technology Add-ons. UCC provides a comprehensive so…☆82Updated this week
- Splunk Docker GitHub Repository☆527Updated 2 weeks ago
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆70Updated 6 months ago
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆193Updated last year
- This repo contains example of raw event examples and possible translations to the OCSF schema.☆52Updated 6 months ago
- Ansible framework providing a fast and simple way to spin up complex Splunk environments.☆132Updated this week
- Contains Logstash related content including tons of Logstash configurations☆254Updated 4 years ago
- A Dynamic test tool for Splunk Technology Add-ons☆64Updated this week