laurel 0.7.3

Transform Linux Audit logs for SIEM usage
Documentation
1
2
3
{"ID":"1628602815.266:2365","SYSCALL":{"arch":"0xc000003e","syscall":59,"success":"yes","exit":0,"items":2,"ppid":3193,"pid":6382,"auid":1000,"uid":0,"gid":0,"euid":0,"suid":0,"fsuid":0,"egid":0,"sgid":0,"fsgid":0,"tty":"pts0","ses":1,"comm":"cat","exe":"/usr/bin/cat","key":"filter-this","ARGV":["0x2557470","0x247b510","0x2565820","0x5bb"]}}
{"ID":"1628602815.266:2366","SYSCALL":{"arch":"0xc000003e","syscall":0,"success":"yes","exit":0,"items":2,"ppid":3193,"pid":6382,"auid":1000,"uid":0,"gid":0,"euid":0,"suid":0,"fsuid":0,"egid":0,"sgid":0,"fsgid":0,"tty":"pts0","ses":1,"comm":"cat","exe":"/usr/bin/cat","key":"filter-this","ARGV":["0x2557470","0x247b510","0x2565820","0x5bb"]}}
{"ID":"1628602815.266:2367","SYSCALL":{"arch":"0xc000003e","syscall":0,"success":"yes","exit":0,"items":2,"ppid":3193,"pid":6382,"auid":1000,"uid":0,"gid":0,"euid":0,"suid":0,"fsuid":0,"egid":0,"sgid":0,"fsgid":0,"tty":"pts0","ses":1,"comm":"cat","exe":"/usr/bin/cat","key":"this-too","ARGV":["0x2557470","0x247b510","0x2565820","0x5bb"]}}