OTRF / Security-Datasets

Re-play Security Events
MIT License
1.61k stars 239 forks source link

Error when shipping to HELK #42

Closed jcastillo725 closed 3 years ago

jcastillo725 commented 3 years ago

I'm encountering an error when trying to ship datasets to HELK.

image

sec-balkan commented 3 years ago

Have you been able to solve it?

blueteambram commented 3 years ago

Try running sudo pip3 install elasticsearch

Cyb3rWard0g commented 3 years ago

Hello @jcastillo725 ! It has been a while since I tried to send data to HELK. However, I know @thomaspatzke does it for his project

https://github.com/thomaspatzke/elk-detection-lab

He contributed the script to the project, but I have not tested it myself. @thomaspatzke , would it be possible whenever you have some time to test it with your project if you do not mind? I know you are very busy so whenever you have time :) Thank you man!

thomaspatzke commented 3 years ago

Sure, Roberto! Can you assign it to me so that it doesn't gets lost? For me it appears that the elasticsearch library is not present.

Cyb3rWard0g commented 3 years ago

Hello @thomaspatzke ! I did not pay attention to the error and got confused with another issue that also talked about sending data to an ELK stack. I thought they were similar ones. Yes the error is pretty straightforward 😂 sorry to bother you with this. I hope you have a great weekend!

thomaspatzke commented 3 years ago

Good occasion to update the link to Mordor to the current version 😉

Cyb3rWard0g commented 3 years ago

Ohhh yes! Yay! 😅