This repository contains a number of useful preset rules and configurations for an Apache Metron cluster.
Profiles contains a series of profiler configurations counting various useful features. These are often used along with Triage rules.
Triage rules set scores against certain types of match. These may be around data from a profile, or from other data in incoming messages and alerts.
Use cases collect these together into a particular end to end picture, often featuring enrichment rules, profiles, and triage rules to address a particular kind of analytic or targeting a particular attack.