Hi all,
Pigtail is a part of Hogzilla IDS, which inserts the Hogzilla events into Snorby's database. Pigtail v1.0 can be downloaded from GitHub .
The attached screenshot refers to a real event, alerted by Hogzilla using k-means clustering.
More is coming...
regards,
PA