Pack That Thing Up
Let’s start by adding the Pack from our esteemed colleague, Ed. Notice that this Pack comes from a colleague and not the Dispensary. Stream makes it easy to share your own Packs and even include versioning!
important
Add the custom Pack
- Make sure
Manageis active in Stream's top nav – select theProcessingsubmenu and clickPacks - Click
Add Pack - Select
Import from URL - Paste in the URL:
https://sandbox.cribl.io/assets/packs/palo-alto-pack.crbl - Enter
secops-palo-enrichin New Pack ID - Click
Import
tip
While you can import from a URL, notice that you can also download the Pack from the URL provided and upload the file itself.
Now that the Pack has been uploaded, let’s see what it contains: One data Route and a complex Pipeline complete with Function groups.
important
- Click
secops-palo-enrich - Click the
firewall_geoip_enrichPipeline hyperlink from thedefaultData Route