Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Incorporate OSSEM #100

Open
Beercow opened this issue Feb 15, 2019 · 2 comments
Open

Incorporate OSSEM #100

Beercow opened this issue Feb 15, 2019 · 2 comments
Labels
enhancement New feature or request

Comments

@Beercow
Copy link

Beercow commented Feb 15, 2019

Framework for normalizing logs.
https://github.com/Cyb3rWard0g/OSSEM

@yugoslavskiy
Copy link
Member

Hello @Beercow ! Thank you for suggestion. We have some references to this repo (for example, here), and we are going to use it in the future.

@yugoslavskiy yugoslavskiy reopened this Mar 27, 2020
@yugoslavskiy yugoslavskiy added the enhancement New feature or request label Mar 27, 2020
@yugoslavskiy
Copy link
Member

yugoslavskiy commented Apr 1, 2020

We've started working on the topic back in April 2019. There were discussions with Roberto and other guys in Hunters Forge slack workspace back in 2019, but mostly without any outcome.

Back in January 2020, we joined a call with Roberto and other folks to discuss yamlizatiom of OSSEM data.

There were 3-4 YAML-structured templates presented, and some of them looked like they can fulfill our needs. We've provided our feedback on that.

I am not quite sure that the final YAML template is actually one of those we voted for. The main reason is that we need most of the field that we have in our Data Needed template, but some of the presented templates were not including some of these fields.

So, this topic needs to be investigated.
If format fits — let's incorporate it.
If not — let's provide details and try to change the format.

I believe that if we will provide a transparent and detailed explanation of what is required from our side, Roberto and guys who were working on YAML translation script will change it, or apply our changes that we will push to their md->yaml translation scripts using Pull Request here on GitHub.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants