streamalert icon indicating copy to clipboard operation
streamalert copied to clipboard

StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.

Results 97 streamalert issues
Sort by recently updated
recently updated
newest added

## Background ## StreamAlert supports a handful of output services (Slack, AWS S3, AWS Lambda, PagerDuty, Phantom...), each which may require different properties for their configuration. For instance, Phantom requires...

improvement

### Background Currently, the CLI command `terraform status` simply prints output based on the config (`variables.json`), and concatenates that with the defined Terraform outputs in the code (mainly user access...

cli
help wanted
improvement

**Problem** Some JSON logs have keys that are dynamic Example: CarbonBlack's `feed.storage.hit.process` - Example key: alliance_data_ Where is `bit9endpointvisibility`, `bit9earlyaccess`, or one of a dozen other feeds. These feed names...

improvement

The current CSVParser class is not designed to properly handle input if it contains a header row. We should either subclass this parser or create a new one that can...

improvement
log parsers

Make it easy to define what clusters a rule should run in Desired properties (very rough draft, open for comment): 1. "Write once, run anywhere" - meaning, write the rule...

rules
RFC

What: - https://www.bro.org/ - Add log schemas to `conf/logs.json` - https://www.bro.org/sphinx/script-reference/log-files.html

help wanted
log schemas

What: - https://suricata-ids.org/ - Add log schemas to conf/logs.json - http://suricata.readthedocs.io/en/latest/output/index.html

help wanted
log schemas

https://aws.amazon.com/step-functions/ Have the ability for alerts to go into step functions for decoration, context fetching or to make desired state change

feature request

**Background** AWS Data Pipelines can log errors to an S3 bucket: http://docs.aws.amazon.com/datapipeline/latest/DeveloperGuide/dp-error-logs.html **Goal** - Identify the log format - Verify if StreamAlert's existing S3 support does support this use-case -...

logs
help wanted

AWS deprecation timeline for python3.7 lambda run time is Nov'23. Could you confirm when the lambdas will be updated to run on the latest version of python.