{"repo":"DCSO/fever","free":true,"listed":false,"github":"https://github.com/DCSO/fever","clone":"git clone https://github.com/DCSO/fever.git","description":"fast, extensible, versatile event router for Suricata's EVE-JSON format","language":"Go","stars":58,"topics":["suricata","eve","json","golang","security","monitoring","pdns","intrusion-detection","bloom-filter","netsec"],"license":null,"category":"analytics","readme_excerpt":"🔥 FEVER The Fast, Extensible, Versatile Event Router (FEVER) is a tool for fast processing of events from Suricata's JSON EVE output. What is meant by 'processing' is defined by a number of modular components, for example facilitating fast ingestion into a database. Other processors implement collection, aggregation and forwarding of various metadata (e.g. aggregated and raw flows, passive DNS data, etc.) as well as performance metrics. It is meant to be used in front of (or as a replacement for) general-purpose log processors like Logstash to increase event throughput as observed on sensors that see a lot of traffic. Building Like any good Go program: Usage It is also possible to use a config file in YAML format (Example). Configuration is cascading: first settings are loaded from the config file and can then be overridden by command line parameters. Running tests The test suite requires a Redis executable in the current path. Most simply, this requirement can be satisfied by just installing Redis. For instance, via apt : Then the test suite can be run via Go's generic testing framework: Suricata settings The tool is designed to consume JSON events from a socket, by default /tmp/suri.sock . This can be enabled using the following setting in suricata.yaml : All JSON is also passed through to another socket, which allows to plug it between Suricata and another log consumer, e.g. Logstash and friends. Another way to consume events is via Redis. Use the -r parameters to specify","default_branch":null,"files":null,"tree":[],"storefront":"/r/DCSO","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/DCSO/fever/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}