BOTES is a security dataset adapted and modified for Elastic Stack from the original Splunk BOTS dataset (Information about Splunk BOTS).
Splunk specific, duplicated and bad parsed fields have been removed from the dataset to make it cleaner and lighter.
BOTES Python script can be used along with ECS Python script to automatically generate files needed to setup Elastic environement (Elasticsearch Index Mapping, Logstash configuration, ...) and use ECS (Elastic Common Schema) format.
Dataset cleaning process is fully documented here : BOTES GitBook documentation
Documentation provides details about each step of cleaning, about matching between original and ECS fields, how to use BOTES and ECS Python scripts and how to setup an already installed Elastic Stack.
Compressed version of cleaned Dataset can be downloaded on the following locations, and are ready to be ingested with Logstash by using configurations provided in the documentation :