mirror of
https://github.com/autistic-symposium/shell-whiz-toolkit.git
synced 2025-11-23 15:40:40 -05:00
| .. | ||
| grabbing_es_data.py | ||
| README.md | ||
| set_log.py | ||
elastalert hacks
curl -s logs.HOST.com:9200/logstash-2017.09.08/_search\?q=ty_params.ProcessName:osqueryd\&size=10000\&sort=@timestamp:desc | jq -r '.hits.hits[]._source.ty_params.Username' | sort | uniq -c | sort -nr