/ecs-mapping

Mapping Corelight or Zeek data to Elastic Common Schema fields

BSD 3-Clause "New" or "Revised" LicenseBSD-3-Clause

Corelight ECS Ingest Pipeline

The repository is compromised of Ingest Pipeline files required to be used with the installer script in the repository
https://github.com/corelight/ecs-templates

The installer in that repository will download the files from this repository therefore using this repository directly is not required nor recommended.

License

The files and automation script are open-source under a BSD license. See COPYINGfor details.

Github Repository Definitions

Elasticsearch templates

https://github.com/corelight/ecs-templates

  • Elasticsearch index templates, component templates, ilm policies, settings, and mappings
  • Install Script

Logstash Pipelines

https://github.com/corelight/ecs-logstash-mappings

  • Logstash pipeline configurations

Ingest Pipelines (This Repository)

https://github.com/corelight/ecs-mapping

  • Ingest pipeline configurations

Kibana Dashboards and Visualizations

https://github.com/corelight/ecs-dashboards

Kibana Security Rules and Alerts

https://github.com/corelight/Elasticsearch_rules