Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Migrate zeek #225

Closed
leehinman opened this issue Aug 5, 2020 · 1 comment · Fixed by #245
Closed

Migrate zeek #225

leehinman opened this issue Aug 5, 2020 · 1 comment · Fixed by #245
Assignees
Labels
Team:SIEM (Deprecated)

Comments

@leehinman
Copy link
Contributor

migrate filebeat x-pack/module/zeek

@leehinman leehinman self-assigned this Aug 5, 2020
@leehinman leehinman added the Team:SIEM (Deprecated) label Aug 5, 2020
@elasticmachine
Copy link

Pinging @elastic/siem (Team:SIEM)

leehinman added a commit to leehinman/integrations that referenced this issue Sep 18, 2020
- capture_loss
- connection
- dce_rpc
- dhcp
- dnp3
- dns
- dpd
- files
- ftp
- http
- intel
- irc
- kerberos
- modbus
- mysql
- notice
- ntlm
- ocsp
- pe
- radius
- rdp
- rfb
- sip
- smb_cmd
- smb_files
- smb_mapping
- smtp
- snmp
- socks
- ssh
- ssl
- stats
- syslog
- traceroute
- tunnel
- weird
- x509

Closes elastic#225
leehinman added a commit that referenced this issue Sep 18, 2020
* Add zeek package

- capture_loss
- connection
- dce_rpc
- dhcp
- dnp3
- dns
- dpd
- files
- ftp
- http
- intel
- irc
- kerberos
- modbus
- mysql
- notice
- ntlm
- ocsp
- pe
- radius
- rdp
- rfb
- sip
- smb_cmd
- smb_files
- smb_mapping
- smtp
- snmp
- socks
- ssh
- ssl
- stats
- syslog
- traceroute
- tunnel
- weird
- x509
- limit visualizations to zeek data
- removed config option for communit_id processor
- synced with filebeat zeek module for ECS 1.6.0 changes

Closes #225
eyalkraft pushed a commit to build-security/integrations that referenced this issue Mar 30, 2022
* Add zeek package

- capture_loss
- connection
- dce_rpc
- dhcp
- dnp3
- dns
- dpd
- files
- ftp
- http
- intel
- irc
- kerberos
- modbus
- mysql
- notice
- ntlm
- ocsp
- pe
- radius
- rdp
- rfb
- sip
- smb_cmd
- smb_files
- smb_mapping
- smtp
- snmp
- socks
- ssh
- ssl
- stats
- syslog
- traceroute
- tunnel
- weird
- x509
- limit visualizations to zeek data
- removed config option for communit_id processor
- synced with filebeat zeek module for ECS 1.6.0 changes

Closes elastic#225
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team:SIEM (Deprecated)
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants