EveBox is a web-based Suricata “eve” event viewer for Elastic Search.
- A web-based event viewer with an “Inbox” approach to alert management.
- Event search.
- An agent for sending Suricata events to the EveBox server (but you can use Filebeat/Logstash instead).
- Embedded SQLite for self-contained installations.
Changelog v0.10.2 2019-01-30
- If EveBox is installing the Elastic Search template, re-configure after installation to figure out the keyword suffix instead of requiring EveBox to be restarted. https://github.com/jasonish/evebox/issues/85
- In agg reports use default min_doc_count of 1 instead of 0. Prevents values from showing in the report that have 0 hits, when the number of results in less than the number of results requested. Affects: Elastic Search. https://github.com/jasonish/evebox/issues/99
- Remove top rrdata from DNS report as its not really valid with DNS v2 alerts. Best to remove it until an alternate metric can be used to report on DNS responses. Closes https://github.com/jasonish/evebox/issues/72.
- Fixed pager button on “Events” view. https://github.com/jasonish/evebox/issues/92
- Fix issue with drop down event type selector on events view page where choosing an event type was taking users back to the index.
- Fix pcap downloads when authentication is on. This requires setting a cookie as this isn’t an XHR/REST style request.https://github.com/jasonish/evebox/issues/90
- Fix doc on adding a user. https://github.com/jasonish/evebox/issues/89
Copyright (c) 2014-2016 Jason Ish
All rights reserved.