Josh Brower
7cbeed985a
Differentiate between event & ingest timestamp
2021-04-13 12:55:40 -04:00
Josh Brower
548f67ca6f
Initial support for Live Queries in Hunt
2021-03-04 18:21:13 -05:00
Josh Brower
13ab4c66eb
Update Osquery Windows Eventlog Parsing
2021-01-27 09:15:54 -05:00
jtgreen-cse
6359e03ba6
fix for Windows events via osquery
...
This change was required to properly let Windows events flow through their specific pipelines. Otherwise, the `temp` field stays around and gets ingested in ES.
2020-10-29 15:03:13 -04:00
Josh Brower
d4f7a07f85
Osquery Parsing fix
2020-08-18 15:54:11 -04:00
Josh Brower
d971d07720
Osquery & WLB Parsing Update for WEL & Sysmon
2020-07-31 16:06:15 -04:00
Josh Brower
65062d93f4
Misc fixes
2020-07-10 19:43:43 -04:00
Josh Brower
8723f8785e
osquery pipeline fix and fail state if errors
2020-05-26 13:05:56 -04:00
Josh Brower
9d4536dcbe
osquery ingest parsing update
2020-05-15 15:05:21 -04:00
Josh Brower
6332509a33
osquery pipeline fix
2020-04-15 20:22:54 -04:00
Josh Brower
634100318e
osquery ingest ecs
2020-04-13 10:58:13 -04:00
Josh Brower
edae63097c
fleet osquery fixes
2020-04-10 16:56:37 -04:00
Josh Brower
0e76447d11
osquery ingest - initial support
2020-04-01 10:17:36 -04:00