Sign inSign up

hasecuritysolutions/es2hive

By hasecuritysolutions

•Updated almost 5 years ago

Image
0

998

hasecuritysolutions/es2hive repository overview

⁠elastic2hive

Elastic SIEM Signals to TheHive Alerts

⁠Installation

  1. Clone the repostory
  2. Add your ES and HIVE configurations to config.json
  3. Modify field_mappings.json to map fields from the detection to Hive Alert artifacts
  4. Run python3 elastic2hive.py

⁠Docker Container

  1. Clone the repository
  2. Follow the steps under Installation
  3. Run docker built -t es2hive .
  4. Run docker run --detach --name es2hive:latest
  5. Enjoy

⁠Docker Swarm

version: '3.7'
services:
  es2hive:
    image: your-registry/es2hive
    container_name: es2hive
    volumes:
      - config.json:/config.json
    networks:
      - elastic
    deploy:
      replicas: 1
      restart_policy:
        condition: on-failure
        delay: 5s
        max_attempts: 10
        window: 120s

networks:
  elastic:
    driver: overlay

⁠Contributors

Special thanks to all those that helped contribute to the project and make it what it is

  • @smapper

⁠Disclaimer

I am not responsible if this doesn't work as intended and it comes with no support expectation but if you report a bug I'll do my best to fix it!

Tag summary

Content type

Image

Digest

Size

336.8 MB

Last updated

almost 5 years ago

docker pull hasecuritysolutions/es2hive:1.2