-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added support for intel.log zeek module #14404
Merged
Merged
Commits on Nov 18, 2019
-
Added support for intel.log zeek module
Enrich the elastic#14150 supporting intel.log Co-Authored-By: Arcuri Davide <dadokkio@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 0383c78 - Browse repository at this point
Copy the full SHA 0383c78View commit details -
Co-Authored-By: Arcuri Davide <dadokkio@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 4502def - Browse repository at this point
Copy the full SHA 4502defView commit details -
example intel.log Co-Authored-By: Arcuri Davide <dadokkio@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for aafc39f - Browse repository at this point
Copy the full SHA aafc39fView commit details -
added default_field: false Co-Authored-By: Arcuri Davide <dadokkio@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for fe6edbd - Browse repository at this point
Copy the full SHA fe6edbdView commit details -
Configuration menu - View commit details
-
Copy full SHA for b9c6677 - Browse repository at this point
Copy the full SHA b9c6677View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8243c87 - Browse repository at this point
Copy the full SHA 8243c87View commit details -
Configuration menu - View commit details
-
Copy full SHA for 17f019e - Browse repository at this point
Copy the full SHA 17f019eView commit details
Commits on Nov 19, 2019
-
Expand dots in zeek.intel.seen Parse ts value without dropping millisecond value Add event.ingested timestamp Convert ingest node pipeline to YAML Save JSON message in event.original
Configuration menu - View commit details
-
Copy full SHA for 0e415d5 - Browse repository at this point
Copy the full SHA 0e415d5View commit details -
Expand dots of all seen.* fields Change name of zeek.intel.seen.fa_file to zeek.intel.seen.f as documented by Zeek.
Configuration menu - View commit details
-
Copy full SHA for 1038599 - Browse repository at this point
Copy the full SHA 1038599View commit details -
Configuration menu - View commit details
-
Copy full SHA for 87a5ae3 - Browse repository at this point
Copy the full SHA 87a5ae3View commit details
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.