Published a month ago
Published a month ago
htayanloo
Updated a month ago
0
If you're running Chaitin SafeLine WAF and shipping logs to Splunk, I built a complete app that turns the raw syslog into something usable.
What's included:
5 prebuilt alerts (disabled by default):
critical attack · high-volume attacker · multi-site attacker · mitigation drop · traffic spike
Workflow actions: right-click any IP / site / rule for drill-down dashboards. Optional OSINT links (VirusTotal / AbuseIPDB / Shodan).
Install:
If it was useful to you, please give it a star. Thank you.
Feedback, issues and PRs welcome. If you want a specific dashboard or alert that fits your workflow, drop a comment and I'll build it.