Skip to content

corelight/Zeek-Endpoint-Enrichment

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

83 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Zeek-Endpoint-Enrichment

Enrich Zeek logs with host information

To enrich all logs with an id field, use the tag "#.#-all".

To enrich all logs with an id field, and the Known Entities, use the tag "#.#-known-all".

To only enrich the conn.log, use the tag "#.#-conn".

To only enrich the conn.log, and the Known Entities, use the tag "#.#-known-conn".

For detailed documentation, see https://docs.corelight.com

About

No description, website, or topics provided.

Resources

License

Stars

4 stars

Watchers

3 watching

Forks

Packages

 
 
 

Contributors

Languages