A Logstash based solution to pull and convert Splunk events into Savvius Vigil events
This repository contains the instructions and files necessary to get IDS events from Splunk into Savvius Vigil. Splunk can be used as SIEM for virtually any IDS. In this example, we use snort.
Refer to the wiki for detailed instructions.