unfetter-analytic
unfetter-analytic copied to clipboard
rearchitect the logstash data collection
Use the fields from STIX 2.0 observed data formats. https://docs.google.com/document/d/1IvkLxg_tCnICsatu2lyxKmWmh1gY2h8HUNssKIE-UIA/edit#heading=h.p49j1fwoxldc
Leverage HA Security's logstash config file methodology https://github.com/HASecuritySolutions/Logstash/tree/master/configfiles
Remove SPARK and move to strickly Elasticsearch query model
This is dependant on #24