corelight / ecs-logstash-mappings
Mapping Corelight or Zeek data to Elastic Common Schema logs
☆12Updated 2 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for ecs-logstash-mappings
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 2 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last week
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆22Updated 2 years ago
- A Zeek log writer plugin that publishes to Kafka.☆46Updated 6 months ago
- Splunk App for Cribl Stream and Edge Observability☆20Updated last week
- Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, S…☆16Updated 3 years ago
- SIEM Logstash parsing for more than hundred technologies☆181Updated this week
- Phantom Apps Repo☆82Updated 3 years ago
- Elastic Security Documentation☆69Updated this week
- A (nearly) production ready Dockered MISP☆230Updated 10 months ago
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆171Updated last month
- Plugin providing native AF_Packet support for Zeek.☆33Updated 7 months ago
- ☆25Updated 3 weeks ago
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆67Updated 7 years ago
- Zeek support for Community ID flow hashing.☆34Updated last year
- The tool for updating your Suricata rules.☆254Updated 4 months ago
- Suricata Verification Tests - Testing Suricata Output☆102Updated this week
- Open source endpoint agent providing host information to Zeek. [v2]☆65Updated 3 weeks ago
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆27Updated 4 years ago
- This repo contains example of raw event examples and possible translations to the OCSF schema.☆33Updated last week
- STIX2 graph visualisation library in JS☆83Updated 3 weeks ago
- CEF codec for Logstash☆22Updated 3 weeks ago
- App examples for Splunk Enterprise☆121Updated 3 months ago
- Alert Wizard plugin for Graylog to manage the alert rules☆47Updated this week
- OASIS TC Open Repository: TAXII 2 Client Library Written in Python☆110Updated 6 months ago
- Wazuh - Splunk App☆50Updated last month
- Cisco Orbital - Osquery queries by Talos☆122Updated 2 months ago
- Docker files for building Zeek.☆86Updated last year
- OASIS TC Open Repository: TAXII 2 Server Library Written in Python☆122Updated 6 months ago
- Collaborative Open Playbook Standard☆150Updated last year