.. |
ala.py
|
Improved test coverage
|
2020-06-13 01:11:08 +02:00 |
arcsight.py
|
Added Humio, Crowdstrike, Corelight
|
2020-05-08 13:41:52 +03:00 |
base.py
|
Revert additional change in base.py
|
2020-07-23 10:47:22 -04:00 |
carbonblack.py
|
Fix wild card and some escaped characters
|
2020-08-18 15:57:13 +07:00 |
csharp.py
|
comments for usage
|
2020-04-11 15:47:23 +02:00 |
data.py
|
Moved Sysmon schema XML from contrib directory into module
|
2019-03-16 00:59:29 +01:00 |
discovery.py
|
Added Humio, Crowdstrike, Corelight
|
2020-05-08 13:41:52 +03:00 |
ee-outliers.py
|
Updated author reference in license
|
2020-05-11 11:47:56 +02:00 |
elasticsearch.py
|
docs: MITRE ATT&CK(R) trademark references removed or adjusted
|
2020-09-30 08:53:52 +02:00 |
exceptions.py
|
Changed copyright notices accordingly
|
2018-07-24 00:01:16 +02:00 |
graylog.py
|
Graylog backend now derived from es-qs
|
2019-11-02 22:56:01 +01:00 |
humio.py
|
Added Humio, Crowdstrike, Corelight
|
2020-05-08 13:41:52 +03:00 |
limacharlie.py
|
Added Humio, Crowdstrike, Corelight
|
2020-05-08 13:41:52 +03:00 |
logiq.py
|
Fixes
|
2020-04-08 23:43:46 +02:00 |
logpoint.py
|
Default configurations for backends
|
2019-11-03 23:32:50 +01:00 |
mdatp.py
|
Updating the mdatp backend file as it is currently impossible to set an ActionType as there is no mapping to EventType
|
2020-06-30 14:49:29 +01:00 |
misc.py
|
Conditional field mapping for null values
|
2019-04-25 23:24:05 +02:00 |
mixins.py
|
Using rule ids as Kibana object id
|
2020-01-30 11:30:01 +01:00 |
netwitness-epl.py
|
add Regular expression support
|
2020-09-14 22:04:47 +02:00 |
netwitness.py
|
Default configurations for backends
|
2019-11-03 23:32:50 +01:00 |
powershell.py
|
partial(?) fix of #762
|
2020-05-16 14:51:58 +03:00 |
qradar.py
|
Remove unnecessary edits from qradar.py
|
2020-07-23 10:34:29 -04:00 |
qualys.py
|
Default configurations for backends
|
2019-11-03 23:32:50 +01:00 |
splunk.py
|
Cleanup: removal of corelight_* backends
|
2020-05-24 22:41:38 +02:00 |
sql.py
|
Remove unused function
|
2020-05-30 01:57:06 +02:00 |
sqlite.py
|
Remove unused function
|
2020-05-30 01:57:06 +02:00 |
stix.py
|
STIX Support keywords (value without field)
|
2020-07-28 18:52:02 +03:00 |
sumologic.py
|
Default configurations for backends
|
2019-11-03 23:32:50 +01:00 |
sysmon.py
|
Fix sysmon backend
|
2020-08-28 12:26:40 +03:00 |
tools.py
|
Conditional field mapping for null values
|
2019-04-25 23:24:05 +02:00 |