sof-elk
sof-elk copied to clipboard
Configuration files for the SOF-ELK VM
How do you feel about this proposal for field names? **Field name standards (always follow):** 1. Only use lower case characters (“first_name” instead of “FirstName”) 2. Avoid special characters except...
parse out PID, PPID, etc, etc.
does this make the data load faster? benchmark and test
it probably makes sense to add some screenshots to the readme
for any [answer] that is an IP, add to [ips] and grok to [answer_ip] for enrichment? passivedns makes this easy since each answer is its own log entry... may need...
for example, bro logs don't all go into the 'logstash' index... conn* goes into netflow, http* into httpdlog, etc. the script needs to accommodate these scenarios, then use 'logstash' as...
create filter plugin that takes a date and IP, then returns a binary flag on whether the IP was identified as a tor exit node at that time. requires historical...
add attrib header to each file as well
eg /configfiles-UNSUPPORTED/foousername/ (update the readme file(s) accordingly.)