laurel 0.7.3

Transform Linux Audit logs for SIEM usage
Documentation
1
{"ID":"1708689989.768:339749193","ANOM_PROMISCUOUS":[{"dev":"veth5f40f62","prom":256,"old_prom":0,"auid":4294967295,"uid":0,"gid":0,"ses":4294967295,"AUID":"unset","UID":"root","GID":"root"}],"SYSCALL":{"arch":"0xc000003e","syscall":44,"success":"yes","exit":40,"items":0,"ppid":1,"pid":13877,"auid":4294967295,"uid":0,"gid":0,"euid":0,"suid":0,"fsuid":0,"egid":0,"sgid":0,"fsgid":0,"tty":"(none)","ses":4294967295,"comm":"dockerd","exe":"/usr/bin/dockerd","key":null,"ARCH":"x86_64","SYSCALL":"sendto","AUID":"unset","UID":"root","GID":"root","EUID":"root","SUID":"root","FSUID":"root","EGID":"root","SGID":"root","FSGID":"root","ARGV":["0xe","0xc002e50000","0x28","0x0"]},"SOCKADDR":[{"saddr":"%10%00%00%00%00%00%00%00%00%00%00%00","SADDR":"{fam=netlink nlnk-fam=16 nlnk-pid=0}"}]}