Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ecs-templates — Corelight 或 Zeek Elastic Common Schema 模板 | Kitploit
工具/GitHubGitHub/corelight/ecs-templates
网络安全实用工具与框架日志分析
GitHubcorelight/ecs-templates

ecs-templates

Corelight 或 Zeek Elastic Common Schema 模板

查看仓库
97656天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

概述

本仓库包含将 Corelight 或 Zeek 日志转换为 Elastic Common Schema(ECS)命名标准并将其存储到 Elastic Stack 部署中所需的一切。该仓库最初于 2019 年发布,与 Elastic Common Schema 同年,至今仍在积极维护和更新。

它支持超过 200 种不同的日志和指标,旨在支持所有环境,同时能够自定义所需和期望的选项以适配每个独特的环境。 我们投入了大量精力来确保对所有环境的支持,同时允许自定义必要和期望的选项,以适应每个独特且各自的部署。

该仓库主要由两部分组成:

  1. Elasticsearch 索引模板、组件模板、ILM 策略、设置和映射
  2. 本仓库及相应的 Ingest Pipelines 或 Logstash Pipelines 的安装脚本

许可证

这些文件和自动化脚本在 BSD 许可证下开源。详见 COPYING。

安装步骤

运行脚本前请阅读所有章节。

  1. 要求
  2. 自定义
  3. 安装
  4. 安装后

1. 要求

  • 使用本仓库中的 corelight_ecs.py 脚本。不支持手动安装模板和管道,因为整个文件中有数百个变量需要由脚本替换。
  • Python 3.6 及以上版本
  • Elasticsearch 8.x 及以上版本
  • 如果使用 Logstash,则需要 Logstash 8.x 及以上版本;如果仍在使用 7.x 版本,则需要 7.17 及以上版本
  • Elasticsearch Datastream 索引策略

2. 自定义

鼓励自定义索引设置、映射、别名和 ILM 策略。因此,该脚本被设计为支持多种类型的自定义(详见下文)。 许多自定义功能可能不需要,但有选项总比没有好。始终建议使用自己的分片/副本数量和 ILM 策略,但除此之外,您不需要自定义太多其他内容。然而,如果您通常在所有部署中自定义索引模板、ingest 管道和 logstash 管道中的许多内容,那么您仍然具备这种能力。

  • 自定义索引名称
    脚本会提示您输入此内容,并自动更新任何需要更新的模板、logstash 管道和/或 ingest 管道
  • 索引设置
    • 分片数量
    • 副本数量
    • 覆盖其他索引设置
    • 您认为适合设置部分组件模板中的任何其他内容
  • 索引映射
    • 覆盖 Elasticsearch 索引字段映射
    • 您认为适合映射部分组件模板中的任何其他内容
  • ILM 策略
    • 自定义 ILM 策略
  • 索引别名
    • 索引模式的别名,例如用于向后兼容或禁用它
  • 自定义 Ingest 管道
    • 在任何 Corelight ingest 管道被调用之前调用您自己的自定义 ingest 管道的能力,且无需修改 Corelight ingest 管道
    • 在所有 Corelight ingest 管道被调用之后调用您自己的自定义 ingest 管道的能力,且无需修改 Corelight ingest 管道
  • 自定义 logstash 管道只需创建一个按字母数字顺序更靠前的文件并加载到同一目录中即可

更多详情请参见以下各节。

自定义索引选项

自定义索引名称

脚本会提示您是否希望为您的数据流选择自定义索引名称/模式。这允许您选择自己的索引命名约定。例如,您可以选择:

  • logs-corelight.conn-default
  • ecs-corelight.conn-default
  • call_it_what_you_will.conn-default
  • logs-corelight.conn-remotesite1

然后,如果您选择了 ingest 管道或 logstash 管道,它还会更新所有必要的索引模板。 不建议更改默认值,因为 Corelight 日志现已设置为可与所有其他类型的 ECS 数据配合使用,并可从诸如 logs-* 之类的 Kibana 数据视图中使用。

对于 MSSP/CSSP 或多网络等多租户环境,您不仅可以在脚本提示中选择数据流的组织部分(即上述 3 个示例中的 default 部分),而且如果您在 filebeat 中或其他方法或挂钩管道中设置了 data_stream.namespace,则管道会设置为尊重该变量(如果已设置)而不覆盖它。只需确保您的 namespace 设置为 Elasticsearch 允许作为索引名称的值(这是一个常见错误,有时并不明显)。

您可以在 Google Sheet 中查看所使用的索引模式以及每个日志的默认值。此外,还列出了每个日志的一些附加信息,如 event.category、event.kind 等。

自定义索引设置 即:分片和副本

每个索引模板都被指定调用一个组件模板,您可以使用该组件模板覆盖索引设置。 因此,您无需修改仓库中的索引模板即可使用您自己的索引设置。

创建以下组件模板或在安装后修改它们。您可以修改的组件模板名称如下:

涵盖所有日志(分为 5 个类别):

  • corelight-ecs-component-metric_log-base-settings@custom
  • corelight-ecs-component-parse_failures-base-settings@custom
  • corelight-ecs-component-protocol_log-base-settings@custom
  • corelight-ecs-component-system_log-base-settings@custom
  • corelight-ecs-component-unknown_log-base-settings@custom

涵盖上述之外的个别日志,这些日志通常需要更具体的自身设置:

  • corelight-ecs-component-protocol_log-conn-base-settings@custom
  • corelight-ecs-component-protocol_log-dns-base-settings@custom
  • corelight-ecs-component-protocol_log-files-base-settings@custom
  • corelight-ecs-component-protocol_log-http-base-settings@custom
  • corelight-ecs-component-protocol_log-smb-base-settings@custom
  • corelight-ecs-component-protocol_log-smtp-base-settings@custom
  • corelight-ecs-component-protocol_log-ssl-base-settings@custom
  • corelight-ecs-component-protocol_log-suricata_corelight-base-settings@custom
  • corelight-ecs-component-protocol_log-syslog-base-settings@custom
  • corelight-ecs-component-protocol_log-various-base-settings@custom
  • corelight-ecs-component-protocol_log-weird-base-settings@custom
  • corelight-ecs-component-protocol_log-x509-base-settings@custom

自定义索引映射 即:字段

每个索引模板都被指定调用一个组件模板,您可以使用该组件模板覆盖字段类型或名称等内容的索引映射。 因此,您无需修改仓库中的索引模板即可使用您自己的索引映射。

创建以下组件模板或在安装后修改它们。您可以修改的组件模板名称如下:

涵盖所有日志(分为 5 个类别):

  • corelight-ecs-component-metric_log-mappings@custom
  • corelight-ecs-component-parse_failures-mappings@custom
  • corelight-ecs-component-protocol_log-mappings@custom
  • corelight-ecs-component-system_log-mappings@custom
  • corelight-ecs-component-unknown_log-mappings@custom

涵盖上述之外的个别日志,这些日志通常需要更具体的自身设置:

  • corelight-ecs-component-protocol_log-conn-mappings@custom
  • corelight-ecs-component-protocol_log-dns-mappings@custom
  • corelight-ecs-component-protocol_log-files-mappings@custom
  • corelight-ecs-component-protocol_log-http-mappings@custom
  • corelight-ecs-component-protocol_log-smb-mappings@custom
  • corelight-ecs-component-protocol_log-smtp-mappings@custom
  • corelight-ecs-component-protocol_log-ssl-mappings@custom
  • corelight-ecs-component-protocol_log-suricata_corelight-mappings@custom
  • corelight-ecs-component-protocol_log-syslog-mappings@custom
  • corelight-ecs-component-protocol_log-various-mappings@custom
  • corelight-ecs-component-protocol_log-weird-mappings@custom
  • corelight-ecs-component-protocol_log-x509-mappings@custom

自定义 ILM 策略策略

每个索引模板都被指定调用一个组件模板,您可以使用该组件模板覆盖 ILM 策略以设置您自己的保留期限。 因此,您无需修改仓库中的索引模板即可使用您自己的 ILM 策略。

创建以下组件模板或在安装后修改它们。您可以修改的组件模板名称如下:

涵盖所有日志(分为 5 个类别):

  • corelight-ecs-component-metric_log-ilm-settings@custom
  • corelight-ecs-component-parse_failures-ilm-settings@custom
  • corelight-ecs-component-protocol_log-ilm-settings@custom
  • corelight-ecs-component-system_log-ilm-settings@custom
  • corelight-ecs-component-unknown_log-ilm-settings@custom

这些将涵盖上述之外的个别日志,这些日志通常需要更具体的自身设置:

  • corelight-ecs-component-protocol_log-conn-ilm-settings@custom
  • corelight-ecs-component-protocol_log-dns-ilm-settings@custom
  • corelight-ecs-component-protocol_log-files-ilm-settings@custom
  • corelight-ecs-component-protocol_log-http-ilm-settings@custom
  • corelight-ecs-component-protocol_log-smb-ilm-settings@custom
  • corelight-ecs-component-protocol_log-smtp-ilm-settings@custom
  • corelight-ecs-component-protocol_log-ssl-ilm-settings@custom
  • corelight-ecs-component-protocol_log-suricata_corelight-ilm-settings@custom
  • corelight-ecs-component-protocol_log-syslog-ilm-settings@custom
  • corelight-ecs-component-protocol_log-various-ilm-settings@custom
  • corelight-ecs-component-protocol_log-weird-ilm-settings@custom
  • corelight-ecs-component-protocol_log-x509-ilm-settings@custom

自定义索引别名

每个索引模板都被指定调用一个组件模板,您可以使用该组件模板覆盖索引别名。 因此,您无需修改仓库中的索引模板即可使用您自己的索引别名。

创建以下组件模板或在安装后修改它们。您可以修改的组件模板名称如下:

涵盖所有日志(分为 5 个类别):

  • corelight-ecs-component-metric_log-aliases@custom
  • corelight-ecs-component-parse_failures-aliases@custom
  • corelight-ecs-component-protocol_log-aliases@custom
  • corelight-ecs-component-system_log-aliases@custom
  • corelight-ecs-component-unknown_log-aliases@custom

这些将涵盖上述之外的个别日志,这些日志通常需要更具体的自身设置:

  • corelight-ecs-component-protocol_log-conn-aliases@custom
  • corelight-ecs-component-protocol_log-dns-aliases@custom
  • corelight-ecs-component-protocol_log-files-aliases@custom
  • corelight-ecs-component-protocol_log-http-aliases@custom
  • corelight-ecs-component-protocol_log-smb-aliases@custom
  • corelight-ecs-component-protocol_log-smtp-aliases@custom
  • corelight-ecs-component-protocol_log-ssl-aliases@custom
  • corelight-ecs-component-protocol_log-suricata_corelight-aliases@custom
  • corelight-ecs-component-protocol_log-syslog-aliases@custom
  • corelight-ecs-component-protocol_log-various-aliases@custom
  • corelight-ecs-component-protocol_log-weird-aliases@custom
  • corelight-ecs-component-protocol_log-x509-aliases@custom

自定义 Ingest 管道

自定义起始 Ingest 管道兜底

在 ingest 管道的开头,在任何 Corelight 管道被调用之前,有一个函数使用名为 corelight-ecs-main-pipeline@custom 的 ingest 管道。 如果您想在 Corelight 管道被调用之前执行某些操作,可以用该名称创建一个 ingest 管道。 如果您不创建该管道,该函数会静默跳过它,因此它是可选的。

下载工具