mlsecproject / combine

Tool to gather Threat Intelligence indicators from publicly available sources
https://www.mlsecproject.org/
GNU General Public License v3.0
654 stars 171 forks source link

Arcsight/CEF Output #147

Open juju4 opened 9 years ago

juju4 commented 9 years ago

Should add a CEF output to inject data in Arcsight.

Have code here https://github.com/juju4/combine/tree/dev but still need more testing

markderijkinfosec commented 9 years ago

Hi,

I would like to add this data to my ArcSight deployments. Let me know if I can assist.

alexcpsec commented 9 years ago

HI, @juju4 ! Could you send a PR with your changes so we could have a look to integrate it back?

@markderijkinfosec you can definitely help by testing if his changes generate the desired outcome.

Thanks for the help, people!

juju4 commented 9 years ago

Hello,

@markderijkinfosec you can try my fork and send me feedback. @alexcpsec There are a few more tests I want to do, hopefully by end of month before doing the pull request.

Thanks

markderijkinfosec commented 9 years ago

Hi,

I should hopefully be ready next week for testing. I already downloaded the fork.