criblpacks / cribl-palo-alto-networksLinks
Process, reduce, and transform Palo Alto Networks Firewall logs.
☆17Updated this week
Alternatives and similar repositories for cribl-palo-alto-networks
Users that are interested in cribl-palo-alto-networks are comparing it to the libraries listed below
Sorting:
- Palo Alto Networks App for Splunk leverages the data visibility provided by Palo Alto Networks next-generation firewalls and endpoint sec…☆107Updated 10 months ago
- This pack is targeted for collections of Window events in the Classic or newer XML format. For events in the Classic format, sometimes th…☆16Updated 2 years ago
- Ansible playbook for installing MineMeld on Linux☆48Updated 4 years ago
- Palo Alto Networks Rule Parser☆16Updated 9 years ago
- Run zeek with zeekctl in docker☆55Updated 11 months ago
- Configuration for a Palo Alto Networks fed ELK Stack with Visualizations☆73Updated 6 years ago
- Splunk Content Control Tool☆116Updated this week
- Shell script to download apps from Splunkbase☆23Updated 5 years ago
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆27Updated 5 years ago
- Skillets is the default holding place for useful Panhandler skillets. These are usually smaller one-off bits that may not require their o…☆12Updated 5 years ago
- A tool for bulk URL queries against Palo Alto Networks' PAN-DB cloud database☆18Updated last year
- SIEM Logstash parsing for more than hundred technologies☆187Updated 2 weeks ago
- Official Palo Alto Networks MineMeld docker☆17Updated 5 years ago
- Splunk Admins application to assist with troubleshooting Splunk enterprise installations☆96Updated 2 weeks ago
- RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high…☆57Updated 3 weeks ago
- Cisco eStreamer client☆24Updated 3 years ago
- TrackMe - Data tracking system for Splunk admins☆50Updated 2 years ago
- Data validator agains Splunk Common Information Model (CIM)☆76Updated last year
- Docker Splunk "Orchestration" bash script (6,000+ lines) to create fully automated pre-configured splunk site-2-site clusters or stand al…☆140Updated 5 years ago
- Phantom Apps Repo☆83Updated 3 years ago
- MineMeld nodes for MISP☆19Updated last year
- App examples for Splunk Enterprise☆147Updated this week
- The Palo Alto Networks Add-on for Splunk allows a Splunk® Enterprise or Splunk Cloud administrator to collect data from Palo Alto Network…☆21Updated 5 years ago
- Syntax highlighting for Splunk .conf files☆77Updated last year
- Splunk Remote Work Insights - Executive Dashboard☆42Updated 5 years ago
- Install a full Splunk Enterprise Cluster or Universal forwarder using an ansible playbook☆53Updated 5 years ago
- Visual Studio Code Extension for Splunk☆93Updated last week
- Splunk (Other Splunk scripts which do not fit into the SplunkAdmins application)☆41Updated 2 months ago
- scripts to configure the Splunk Universal Forwarder in a locked down state☆40Updated 6 years ago
- The Project can be used to integrate QRadar with MISP Threat Sharing Platform☆39Updated 3 years ago