Integration of Bro-IDS and ELK stack
-
Updated
May 26, 2017
Integration of Bro-IDS and ELK stack
An Ubuntu 16.04 build containing Suricata, PulledPork, Bro, and Splunk
Brostash Logstash pipeline
🐦 A fluentd config for zeek
Patches for cross-compiling Bro IDS with Buildroot.
Bro IDS Dockerfile
brostash: Linux distribution based on Debian and focusing on network security events collection
Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)
Simple logfile parser for Bro IDS
Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings
Add a description, image, and links to the bro-ids topic page so that developers can more easily learn about it.
To associate your repository with the bro-ids topic, visit your repo's landing page and select "manage topics."