criblio / collector-templatesLinks
Templates for Cribl Stream Collectors
☆54Updated 3 weeks ago
Alternatives and similar repositories for collector-templates
Users that are interested in collector-templates are comparing it to the libraries listed below
Sorting:
- Splunk Content Control Tool☆124Updated this week
- RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high…☆61Updated 2 weeks ago
- Contains research.splunk.com site code☆11Updated last year
- This repository contains Community and Field contributed content for LogScale☆303Updated this week
- Discover for Cloud and Containers Azure☆30Updated last week
- Azure Functions for getting data in to Splunk☆33Updated last month
- TrackMe - Data tracking system for Splunk admins☆50Updated 2 years ago
- The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆44Updated 5 years ago
- Programming Microsoft Sentinel book☆25Updated last year
- Splunk App for Cribl Stream and Edge Observability☆25Updated 4 months ago
- scripts using splunk application lookup-editor endpoint. Download, upload and update splunk lookups content☆31Updated last year
- ☆98Updated 3 years ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆118Updated 8 months ago
- 🚨ATTENTION🚨 The Security Stack Mappings have migrated to the Center’s Mappings Explorer project. See README below. This repository is k…☆390Updated last year
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆215Updated last month
- Web based S1 query navigator for one-click threat hunting☆24Updated 4 years ago
- MISP to Sentinel integration☆77Updated this week
- ☆88Updated 9 months ago
- A list of Splunk queries that I've collected and used over time.☆88Updated 5 years ago
- Command line tool to interact with Chronicle's Config Based Normalizer (CBN) APIs.☆31Updated 2 years ago
- Splunk (Other Splunk scripts which do not fit into the SplunkAdmins application)☆41Updated 2 months ago
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆166Updated last week
- ☆43Updated last week
- Integration tools for TheHive and Azure Sentinel☆13Updated 5 years ago
- This is a repository of vendor-agnostic workflows provided for those interested in deploying Security Orchestration, Automation, and Resp…☆89Updated 4 years ago
- Home for Splunk security datasets.☆126Updated 5 years ago
- Splunk Connect for Syslog☆171Updated this week
- Scripted inputs designed to address common use-cases in forwarder misconfigurations in a Splunk deployment☆35Updated last year
- The Business Email Compromise Guide sets out to describe 10 steps for performing a Business Email Compromise (BEC) investigation in an Of…☆265Updated 4 years ago
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆54Updated 2 years ago