OTRF/Security-Datasets

Error when shipping to HELK

jcastillo725 opened this issue ยท 7 comments

I'm encountering an error when trying to ship datasets to HELK.

image

Have you been able to solve it?

Try running sudo pip3 install elasticsearch

Hello @jcastillo725 ! It has been a while since I tried to send data to HELK. However, I know @thomaspatzke does it for his project

https://github.com/thomaspatzke/elk-detection-lab

He contributed the script to the project, but I have not tested it myself. @thomaspatzke , would it be possible whenever you have some time to test it with your project if you do not mind? I know you are very busy so whenever you have time :) Thank you man!

Sure, Roberto! Can you assign it to me so that it doesn't gets lost? For me it appears that the elasticsearch library is not present.

Hello @thomaspatzke ! I did not pay attention to the error and got confused with another issue that also talked about sending data to an ELK stack. I thought they were similar ones. Yes the error is pretty straightforward ๐Ÿ˜‚ sorry to bother you with this. I hope you have a great weekend!

Good occasion to update the link to Mordor to the current version ๐Ÿ˜‰

Ohhh yes! Yay! ๐Ÿ˜