Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

pull analytics from Unfetter Discover and run against elasticsearch #57

Open
4 tasks
infosec-alchemist opened this issue Mar 30, 2018 · 0 comments
Open
4 tasks

Comments

@infosec-alchemist
Copy link
Contributor

infosec-alchemist commented Mar 30, 2018

in addition to the CAR analytics, we want to poll the Unfetter Discover for the analytic scripts, and then run those analytics against Unfetter Analytic

  • The data model in Elasticsearch must match the scripted analytic
  • Be able to support AT LEAST one analytic, which is very focused on an Event ID for easy testing
  • Must push the alert and the sighting
  • Must be able to pull ONE observed data object. But not sure how to manage that.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant