<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Suricata/Bro Data Models in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Suricata-Bro-Data-Models/m-p/420019#M3694</link>
    <description>&lt;P&gt;So I am getting data ingested from Bro/Zeek and Suricata via the TA's for said applications.  I want to build data models for them and wanted to see if anyone has anything built for Bro/Zeek or Suricata.  &lt;/P&gt;

&lt;P&gt;So far I built a "data model" for suricata (called suricata) &lt;/P&gt;

&lt;P&gt;Then a Root Event (index=suricata source=suricata sourcetype=suricata)&lt;BR /&gt;
From there I have Child &lt;BR /&gt;
Src_ip  (src_ip=192.168.*)&lt;BR /&gt;
Then children of that are broken out like this&lt;BR /&gt;
--Severity&lt;BR /&gt;
------Severity I  (suricata.attack.severity=1)&lt;BR /&gt;
------Severity II (suricata.attack.severity=2)&lt;BR /&gt;
------Severity III(suricata.attack.severity=3)&lt;BR /&gt;
--Category&lt;/P&gt;

&lt;P&gt;Dest_ip&lt;/P&gt;

&lt;P&gt;Well you get the point.&lt;BR /&gt;&lt;BR /&gt;
Is there a better way of doing this, or am I on sort of the right track?  &lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 00:12:16 GMT</pubDate>
    <dc:creator>ddecker03</dc:creator>
    <dc:date>2020-09-30T00:12:16Z</dc:date>
    <item>
      <title>Suricata/Bro Data Models</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Suricata-Bro-Data-Models/m-p/420019#M3694</link>
      <description>&lt;P&gt;So I am getting data ingested from Bro/Zeek and Suricata via the TA's for said applications.  I want to build data models for them and wanted to see if anyone has anything built for Bro/Zeek or Suricata.  &lt;/P&gt;

&lt;P&gt;So far I built a "data model" for suricata (called suricata) &lt;/P&gt;

&lt;P&gt;Then a Root Event (index=suricata source=suricata sourcetype=suricata)&lt;BR /&gt;
From there I have Child &lt;BR /&gt;
Src_ip  (src_ip=192.168.*)&lt;BR /&gt;
Then children of that are broken out like this&lt;BR /&gt;
--Severity&lt;BR /&gt;
------Severity I  (suricata.attack.severity=1)&lt;BR /&gt;
------Severity II (suricata.attack.severity=2)&lt;BR /&gt;
------Severity III(suricata.attack.severity=3)&lt;BR /&gt;
--Category&lt;/P&gt;

&lt;P&gt;Dest_ip&lt;/P&gt;

&lt;P&gt;Well you get the point.&lt;BR /&gt;&lt;BR /&gt;
Is there a better way of doing this, or am I on sort of the right track?  &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:12:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Suricata-Bro-Data-Models/m-p/420019#M3694</guid>
      <dc:creator>ddecker03</dc:creator>
      <dc:date>2020-09-30T00:12:16Z</dc:date>
    </item>
  </channel>
</rss>

