Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add taxonomy examples #1135

Merged
merged 23 commits into from Nov 4, 2020
Merged

Add taxonomy examples #1135

merged 23 commits into from Nov 4, 2020

Conversation

mavam
Copy link
Member

@mavam mavam commented Nov 2, 2020

馃摂 Description

This PR adds some example concepts for VAST's builtin canonical taxonmy.

馃摑 Checklist

  • Discuss how we ship our taxonomy declarations and definitions
  • All user-facing changes have changelog entries.
  • The changes are reflected on docs.tenzir.com/vast, if necessary.
  • The PR description contains instructions for the reviewer, if necessary.

馃幆 Review Instructions

File-by-file feels best.

@mavam mavam changed the title Replace splunk-to-vast with more general script Add taxonomy examples Nov 2, 2020
@mavam mavam added the feature New functionality label Nov 2, 2020
@mavam mavam marked this pull request as ready for review November 3, 2020 18:53
Copy link
Member

@tobim tobim left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is very much needed.

I think we should change the load handler in the type-registry to recurse into subdirectories. Let's do that in a separate PR though.

schema/sysmon.yaml Show resolved Hide resolved
schema/sysmon.yaml Show resolved Hide resolved
Copy link

@meta-cretin meta-cretin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good

@mavam mavam force-pushed the topic/canonical-taxonomy-scaffold branch 3 times, most recently from 542211a to 1cb6a7a Compare November 4, 2020 13:01
@mavam mavam requested a review from tobim November 4, 2020 13:01
tobim
tobim previously approved these changes Nov 4, 2020
@tobim tobim dismissed their stale review November 4, 2020 13:15

Too quick.

@mavam mavam requested a review from tobim November 4, 2020 13:27
@mavam mavam force-pushed the topic/canonical-taxonomy-scaffold branch from eb05f93 to 20c4cbb Compare November 4, 2020 16:03
@mavam mavam force-pushed the topic/canonical-taxonomy-scaffold branch from 1f7a57c to 353f459 Compare November 4, 2020 19:34
The Suricata data set has 1183 IP addresses with src_ip equal to
192.168.168.100 and the Zeek conn.log 23. In sum, this is 1206.
Copy link
Member

@tobim tobim left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested additionally with some internal sysmon data. Did not attempt to verify the mappings.

@mavam mavam merged commit 442cfe5 into master Nov 4, 2020
@mavam mavam deleted the topic/canonical-taxonomy-scaffold branch November 4, 2020 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
feature New functionality
Projects
None yet
3 participants