Mike Reeves
|
0b7568e08f
|
Update soc.json with default search info
|
2020-05-12 13:57:40 -04:00 |
|
Josh Brower
|
6332509a33
|
osquery pipeline fix
|
2020-04-15 20:22:54 -04:00 |
|
Wes Lambert
|
59787a6532
|
update parsing for Zeek files
|
2020-04-14 13:08:31 +00:00 |
|
Josh Brower
|
634100318e
|
osquery ingest ecs
|
2020-04-13 10:58:13 -04:00 |
|
Josh Brower
|
edae63097c
|
fleet osquery fixes
|
2020-04-10 16:56:37 -04:00 |
|
Wes Lambert
|
9e50387eec
|
update ingest files
|
2020-04-05 20:40:00 +00:00 |
|
Wes Lambert
|
e023aeb9be
|
use agent name for observer name
|
2020-04-01 21:27:25 +00:00 |
|
weslambert
|
f13093dc51
|
Add message rename
|
2020-04-01 11:31:57 -04:00 |
|
Josh Brower
|
0e76447d11
|
osquery ingest - initial support
|
2020-04-01 10:17:36 -04:00 |
|
Wes Lambert
|
eacd3c9bfd
|
update zeek.common
|
2020-03-31 00:36:42 +00:00 |
|
Wes Lambert
|
ad50093315
|
add community_id parsing for ingest
|
2020-03-30 15:49:36 +00:00 |
|
Wes Lambert
|
93c3c86e2f
|
update wazuh fields and category
|
2020-03-30 14:24:01 +00:00 |
|
Wes Lambert
|
ef808875f4
|
fix ossec fields
|
2020-03-24 15:42:31 +00:00 |
|
Wes Lambert
|
083c588a87
|
add some more fields
|
2020-03-24 03:43:31 +00:00 |
|
Wes Lambert
|
a5ff21c528
|
remove agent field for non-Wazuh logs
|
2020-03-17 15:20:46 +00:00 |
|
Wes Lambert
|
b80e7fedcb
|
remove agent field for non-Wazuh logs
|
2020-03-17 15:20:31 +00:00 |
|
Wes Lambert
|
488858f8bc
|
remove beat field removal
|
2020-03-17 15:19:08 +00:00 |
|
Wes Lambert
|
c52220330b
|
modify pipelines
|
2020-03-14 12:03:32 +00:00 |
|
Wes Lambert
|
648b0ba790
|
remove old config
|
2020-03-11 12:14:22 +00:00 |
|
Wes Lambert
|
9ad16e8c71
|
upadte ingest config
|
2020-03-11 12:13:53 +00:00 |
|
Wes Lambert
|
b1203cfb9f
|
add initial Strelka ingest config
|
2020-03-03 21:20:45 +00:00 |
|
Wes Lambert
|
ec6638a276
|
src/dst ip/port fields to ECS
|
2020-03-02 19:10:18 +00:00 |
|
Wes Lambert
|
e4fee51ed6
|
Change Bro Files source to file_source
|
2020-03-02 19:09:24 +00:00 |
|
doug
|
cb899943aa
|
incoming bro_tunnel logs should go to bro_tunnels
|
2019-09-24 14:00:22 -04:00 |
|
doug
|
8472b24a67
|
parse Bro logs using Elasticsearch ingest node
|
2019-09-23 16:04:23 -04:00 |
|