splunk
Here are 392 public repositories matching this topic...
Hi! I've recently become more interested in structured logging, and have looked into a few structured logging libraries.
You get amazing power when you dump the logs from all of your different systems and sources into a centralized log store, and can then view and analyze them as one whole.
What I've noticed though is that the various structured logging frameworks all save JSON log entries i
-
Updated
Mar 24, 2020 - Python
-
Updated
Apr 23, 2020 - PowerShell
-
Updated
Jun 24, 2019 - Python
Document helm chart
Values should be nicely documented in a markdown table in the readme, not just as yaml in values.yaml. This is the standard way of documenting helm charts in the default stable repo. Will make the chart more accessible to newcomers.
-
Updated
May 21, 2020 - Scala
-
Updated
Jun 2, 2016 - PowerShell
-
Updated
Mar 21, 2018
-
Updated
Mar 31, 2020 - YARA
-
Updated
May 25, 2016 - Python
-
Updated
Mar 18, 2018 - Python
-
Updated
May 19, 2020 - HTML
-
Updated
Mar 20, 2020 - Vim script
key-file("/opt/syslog-ng/tls/server.key")
cert-file("/opt/syslog-ng/tls/server.pem")
The default/tags.conf for following have 'session' enabled instead of 'communicate'. As per the Network_Sessions CIM, only DHCP and VPN traffic should be having tags - Network and Sessions. Pls review/validate and update the conf to the below in the next release [ same seen in version 6.1.1 - https://splunkbase.splunk.com/app/2757/]
https://docs.splunk.com/Documentation/CIM/4.12.0/User/NetworkS
What would you like to be added:
Docs example for ciphers array option
https://github.com/splunk/fluent-plugin-splunk-hec#ciphers-array
Why is this needed:
I am deploying SCK 1.3.0 charts and experimenting with security settings by hardening the sslVersions in server.conf & with HEC inputs.conf.
-
Updated
May 13, 2020 - Go
-
Updated
May 18, 2020 - JavaScript
-
Updated
Sep 14, 2018 - Python
-
Updated
Apr 23, 2020 - Python
-
Updated
Nov 13, 2019 - Java
Improve this page
Add a description, image, and links to the splunk topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the splunk topic, visit your repo's landing page and select "manage topics."
Someone should map publicly available EVTX samples to Sigma rules. This would enable us to automatically test the correctness of generated queries.
Known security-related EVTX repositories:
Feel free to extend the list.
Mapping should be:
Sigma rule -> Repository/EVTX ( -> expected matched