BOTES Prerequisites
This page describe which packages are needed to launch scripts and commands used to sanitize the different JSON files from Splunk and generate all Elastic related files.
Install Python 3.7.X
Install jq
jq allow easy and fast JSON processing. (More information here : https://stedolan.github.io/jq/)
Install Go
Install Python packages
Install Git
Logstash configuration
Download Logstash configuration files from the following links and copy them in /etc/logstash/conf.d/
folder.
Logstash configuration file
Download Link
fgt_utm
nessus-scan
winevent-application
winevent-security
winevent-system
xmlwineventlog-sysmon
Elasticsearch Index Template
Elasticsearch Index Mapping for BOTES Dataset, already modified and ready to be used can be downloaded here : https://botes.s3-us-west-1.amazonaws.com/botes-index-mapping/template.json
Upload Elasticsearch Index Mapping template with the following command and your environment :
Date format
Because some dates are in specific format, Elasticsearch Index Template need to be modified. Following formats have been added in Date fields :
Last updated
Was this helpful?