Pack That Thing Up
Let’s start by adding the Pack from our esteemed colleague, Ed. Notice that this Pack comes from a colleague and not the Dispensary. Stream makes it easy to share your own Packs and even include versioning!
important
Add the custom Pack
- Make sure
Manage
is active in Stream's top nav – select theProcessing
submenu and clickPacks
- Click
Add Pack
- Select
Import from URL
- Paste in the URL:
https://sandbox.cribl.io/assets/packs/palo-alto-pack.crbl
- Enter
secops-palo-enrich
in New Pack ID - Click
Import
tip
While you can import from a URL, notice that you can also download the Pack from the URL provided and upload the file itself.
Now that the Pack has been uploaded, let’s see what it contains: One data Route and a complex Pipeline complete with Function groups.
important
- Click
secops-palo-enrich
- Click the
firewall_geoip_enrich
Pipeline hyperlink from thedefault
Data Route