- socket []string: socket name
- zeros boolean: If false, it will not send measurments with value 0
The Suricata plugin sends dump-counters command to Suricata unix socket Threads are used as tags
unsigned int ip_total_len = (unsigned int)ntohs((ip_hdr->ip_len)); | |
unsigned int real_len = 14 + ip_total_len; | |
unsigned int dif = (*pkthdr)->caplen - real_len; | |
if (dif > 0 && dif < 32) | |
{ | |
(*pkthdr)->caplen -= dif; | |
(*pkthdr)->len -= dif; | |
} |
curl -XPOST '10.242.11.3:9200/_cluster/reroute' -d '{ | |
"commands" : [ | |
{ | |
"allocate" : { | |
"index" : "sessions-160420h14", "shard" : 1, "node" : "es-1-data2-c" | |
} | |
} | |
] | |
}' |
import sys | |
reload(sys) | |
sys.setdefaultencoding("utf-8") | |
from os import listdir | |
from os.path import isfile, join | |
import gzip | |
import apache_log_parser | |
from elasticsearch import Elasticsearch | |
from elasticsearch.helpers import bulk |
The Suricata plugin sends dump-counters command to Suricata unix socket Threads are used as tags
package main | |
import "fmt" | |
import "encoding/pem" | |
import "encoding/asn1" | |
import "math/big" | |
import "time" | |
import "os" | |
import "io/ioutil" |
import nmsg | |
import wdns | |
import re | |
def _parse_DKIM(data): | |
if not re.search(r'v\=DKIM', data): | |
return None | |
ret = dict() |
# A bot that joins channels and send the events is sees to elasticsearch. | |
# in bulks ;) | |
''' | |
curl -XPUT "http://localhost:9200/_template/abuh" -d ' { | |
"template": "*@conference*", | |
"settings": { | |
"index.refresh_interval": "5s", | |
"index.number_of_shards": 1, |
""" | |
! testing without XMPP server | |
for real life use: | |
from idstools import unified2 | |
import idiokit | |
from abusehelper.core import bot | |
class Unified2Bot(bot.FeedBot): |
// ES6 | |
/* | |
moloch sessions.csv field names | |
[ 'Protocol', | |
' First Packet', | |
' Last Packet', | |
' Source IP', |
digraph G { | |
subgraph cluster_cap{ | |
softflow; | |
suricata; | |
bro; | |
moloch_cap; | |
} | |
{rank=same; softflow,suricata,bro,moloch_cap } |