{"repo":"DCSO/balboa","free":true,"listed":false,"github":"https://github.com/DCSO/balboa","clone":"git clone https://github.com/DCSO/balboa.git","description":"server for indexing and querying passive DNS observations","language":"C","stars":50,"topics":["pdns","passive","dns","golang","graphql","suricata","api","security","monitoring","rocksdb"],"license":null,"category":"api-integrations-sdks","readme_excerpt":"📑 balboa balboa is the BAsic Little Book Of Answers. It consumes and indexes observations from passive DNS collection, providing a GraphQL interface to access the aggregated contents of the observations database. We built balboa to handle passive DNS data aggregated from metadata gathered by Suricata. The API should be suitable for integration into existing multi-source observable integration frameworks. It is possible to produce results in a Common Output Format compatible schema using either a GraphQL API (see below) or a REST API compatible with CIRCL's. The balboa software... - is fast for queries and input/updates - implements storage using pluggable backends, potentially on separate machines - supports tracking and specifically querying multiple sensors - makes use of multiple cores for query and ingest - accepts input from multiple sources simultaneously - HTTP (POST) - AMQP - Unix socket - network socket (NMSG format only) - can tag and filter observations based on various properties - can store observations to one or multiple backends based on matched selectors - accepts various input formats - JSON-based - FEVER - gopassivedns - Packetbeat (via Logstash) - Suricata EVE DNS v1 and v2 - flat text file - Edward Fjellskål's PassiveDNS tabular format (default order -f SMcsCQTAtn ) - binary - Farsight Security NMSG format via network socket Building and Installation This will drop a balboa executable in your Go bin path. To build the backends: This will create a binary e","default_branch":null,"files":null,"tree":[],"storefront":"/r/DCSO","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/DCSO/balboa/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}