matanolabs / matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
https://matano.dev
Apache License 2.0
1.42k stars 98 forks source link

Remove bracket in VRL to fix o365 log ingest #182

Closed clairecasalnova-cisa closed 8 months ago

clairecasalnova-cisa commented 9 months ago

Removing a bracket in the VRL to allow for ingestion of O365 logs.

This contribution is made by Claire Casalnova as an employee of the Cybersecurity and Infrastructure Security Agency (CISA), a subdivision of the Department of Homeland Security (DHS) and is considered a government work under 17 USC 105. United States copyright is not asserted. International rights are reserved consistent with the license of this package. For questions about this contribution, please contact the author or licensing@cisa.dhs.gov.