Skip to content

Instantly share code, notes, and snippets.

@cyberno-ir
cyberno-ir / elk-stack-log.yml
Created March 12, 2023 16:21
Cyberno log processor for ELK Stack (Filebeat)
- type: filestream
id: cyberno-products
enabled: true
paths:
- /var/log/syslog
processors:
- drop_event:
when:
not.contains:
message: "User_Email"
@cyberno-ir
cyberno-ir / kiosk-decoder.xml
Last active March 11, 2023 15:58
Cyberno decoder and rule for Wazuh XDR
<decoder name="kiosk">
<program_name>main</program_name>
</decoder>
<decoder name="kiosk_child">
<parent>kiosk</parent>
<prematch>User_Email: (\S*) User_IP: (\S*) User_Agent: (\.*) Log: (\.*) Extra: </prematch>
<plugin_decoder offset="after_prematch">JSON_Decoder</plugin_decoder>
</decoder>