Skip to content

Instantly share code, notes, and snippets.


Andrew Kroh andrewkroh

View GitHub Profile
andrewkroh / netusergetinfo.go
Last active Jun 3, 2022
NetUserGetInfo tester tool for Windows
View netusergetinfo.go
package main
import (
andrewkroh / winlogbeat.yml
Created May 19, 2022
Winlogbeat script to log specific event IDs
View winlogbeat.yml
- name: Security
ignore_older: 1h
- script:
lang: javascript
source: |
var console = require("console");
var ids = {
andrewkroh /
Last active Jun 28, 2022
Routing Filebeat data to a Fleet integration data stream

DRAFT: Routing Filebeat data to a Fleet integration data stream

This is an unofficial tutorial that may be useful to users that are in the process of migrating to to Elastic Agent and Fleet. It explains the steps to route some Filebeat data into a data stream managed by a Fleet integration package.

Install the Fleet integration

Installing a Fleet integration sets up all of its data streams and dashboards. There are two methods to install. In these examples we install the Hashicorp Vault 1.3.1 integration.

Use Kibana (easiest)

andrewkroh /
Last active Sep 1, 2022
Bash script to dump wireguard peers to JSON
#!/usr/bin/env bash
# Licensed to Elasticsearch B.V. under one or more contributor
# license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright
# ownership. Elasticsearch B.V. licenses this file to you under
# the Apache License, Version 2.0 (the "License"); you may
# not use this file except in compliance with the License.
# You may obtain a copy of the License at
andrewkroh / 46203-dimmer.xml
Last active Jan 6, 2021
Home Assistant 2020.12.2 Patch for GE Jasco jasco_products_unknown_type_4944_id_3235
View 46203-dimmer.xml
<!-- GE(Jasco) 46203 Z-Wave Plus Dimmer Switch -->
<!-- Configuration Parameters - per -->
<Product Revision="1" xmlns="">
<MetaDataItem name="OzwInfoPage"></MetaDataItem>
<MetaDataItem name="ProductPic">images/ge/46203-dimmer.png</MetaDataItem>
<MetaDataItem id="3235" name="ZWProductPage" type="4944"></MetaDataItem>
<MetaDataItem name="Name">In-Wall Smart Dimmer </MetaDataItem>
<MetaDataItem name="ProductManual">;filename=MarketCertificationFiles/3323/14294.46203.ZW3010%20Binder.pdf</MetaDataItem>
<MetaDataItem id="3235" name="FrequencyName" type="4944">U.S. / Canada / Mexico</MetaDataItem>
andrewkroh / symantec-endpoint-pipeline.json
Last active Apr 21, 2021
Symantec Endpoint Elasticsearch Ingest Node Pipeline (POC)
View symantec-endpoint-pipeline.json
"description": "Pipeline for parsing Symantec Endpoint logs",
"processors": [
"set": {
"field": "event.original",
"value": "{{{message}}}"
andrewkroh / citrix-netscaler-pipeline.json
Last active Dec 15, 2020
Citrix Netscaler Elasticsearch Ingest Node Pipeline
View citrix-netscaler-pipeline.json
"description": "Pipeline for parsing Citrix Netscaler logs",
"processors": [
"script": {
"description": "set event.original",
"lang": "painless",
"source": "def event = ctx.event;\nif (event == null) {\n event = [:];\n ctx['event'] = event;\n}\nevent['original'] = ctx.message;\n"
andrewkroh /
Last active Jul 26, 2022
Adding event.ingested and lag calculations to Winlogbeat events

Adding event.ingested and lag calculations to Winlogbeat events

Create an Ingest Pipeline that will add four fields:

  • event.ingested - Time when the event was processed by Elasticsearch.
  • - Time difference in milliseconds between @timestamp and event.created. This measures how long it took for Winlogbeat read the event from the event log (for WEC this includes the delivery time from forwarder to collector).
  • event.lag.ingest - Time difference in milliseconds between event.created and event.ingested. This measures the time between Winlogbeat reading the event (time when it "created" the document) to when it was written to Elasticsearch.
andrewkroh / functions
Created Sep 22, 2020
RHEL 6 /etc/rc.d/init.d/functions from initscripts-9.03.61-1.el6.centos.x86_64
View functions
# -*-Shell-script-*-
# functions This file contains functions to be used by most or all
# shell scripts in the /etc/init.d directory.
# Make sure umask is sane
umask 022
andrewkroh / howto.txt
Last active May 17, 2022
Microsoft-Windows-Windows Defender Event Log Message Resources
View howto.txt
800, AntiVirus
801, AntiSpyware
802, Antimalware
803, Full
804, Delta
805, Full Scan
806, Quick Scan
807, Custom Scan
808, Remove
809, Quarantine