Issues
- 1
Format Python scripts with Black
#289 opened by za - 11
M365 UAL JSON Logs Not Parsed
#285 opened by joshlemon - 6
Missing ZipFileName and FileSizeBytes fields in UAL logs for SharePoint/OneDrive folder download operations
#340 opened by dsusin - 0
nfdump2sof-elk.sh debug issue
#339 opened by philhagen - 3
- 1
Sysmon logs not being parsed by logstash
#335 opened by matthewerobison - 1
Refine post-merge hook script
#330 opened by philhagen - 1
- 2
remove the dynamic heap size calculations
#286 opened by philhagen - 4
domain-stats no longer works due to refactor
#319 opened by StarkZarn - 6
Request for more Zeek JSON log support
#303 opened by davidszili - 2
Consider "time in pipeline" calculation
#310 opened by philhagen - 14
- 0
convert iptables uptime to float
#315 opened by philhagen - 1
Fix Azure logstash parser in public release
#296 opened by Pierre450 - 0
update nfdump version
#287 opened by philhagen - 2
Root volume does not exist. Getting this issue when I am trying this Image with HyperV
#334 opened by Abhishekpathania01 - 4
EVTX in JSON format not being interpretted.
#290 opened by gru3zi - 1
Enable Security for ELK stack
#333 opened by Aquariius - 8
Best practice for local Evtx ingestion
#332 opened by aarislarsen - 9
azure-vpcflow2sof-elk.py generates empty output
#331 opened by Jurkiseczek - 0
- 13
- 9
- 0
- 0
Live NetFlow fails with latest filebeat
#324 opened by philhagen - 1
SOF-ELK CentOS end of life
#292 opened by maersk-matthewkelly - 1
Azure Storage Logs StorageWrite not parsed
#321 opened by tuzux8 - 6
NetFlow UDP 9995 not listening
#320 opened by stijnos1991 - 2
Logstash randomly crashing when starting
#317 opened by BrianMer - 0
update snare parsing
#318 opened by philhagen - 1
- 1
Broken link in Wiki/Virtual Machine README - Plaso
#313 opened by BrianMer - 1
Broken link in Wiki/KAPE-Support
#311 opened by BrianMer - 3
Create cloud acquisition/export README document
#275 opened by philhagen - 1
increase LS thread stack size
#299 opened by philhagen - 2
Experiment with removing filebeat metadata
#297 opened by philhagen - 2
update filebeat inputs to use filestream
#295 opened by philhagen - 2
- 1
Use uncompressed filebeat shipping
#302 opened by philhagen - 1
SOF-ELK integrate with opensearch
#301 opened by oodog0126 - 3
- 3
Parse additional Google Workspace Email logs
#294 opened by megan201296 - 1
Typo in wiki
#300 opened by Pierre450 - 6
Parse Additional Fields from CloudTrail
#293 opened by vikas891 - 4
- 7
Logstash Azure parser: add GraphAPI log
#282 opened by Pierre450 - 0
Move `asnstr` to runtime fields
#277 opened by philhagen - 0
Ship with old-license GeoIP databases
#279 opened by philhagen - 15
Missing IIS file format
#278 opened by funkwhatyouheard