Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Timefilter save #2977

Open
hasamba opened this issue Nov 12, 2023 · 2 comments
Open

Timefilter save #2977

hasamba opened this issue Nov 12, 2023 · 2 comments

Comments

@hasamba
Copy link

hasamba commented Nov 12, 2023

i imported a timeline into timesketch,
i filter by several time filters i know the attacker was on the system,
when i switch from saved search to another the filters disappear.

it would be great if i can save all those filters to use in a later queries without having to entering them again.

thanks

@jkppr
Copy link
Collaborator

jkppr commented Nov 16, 2023

Thanks for the input @hasamba
It is a great idea and I can see how this will help with the UX of the general analysis workflow. I'll get it on the roadmap 👍

@jkppr
Copy link
Collaborator

jkppr commented Nov 22, 2023

Some brainstorming ideas for this feature:

  • first iteration: Have a list of last used time filters available for searches. e.g. in the search omnibox or when clicking the "Add timefilter" button as a quick selection.

    • This should the quite straightforward to implement, since we have the information already stored with the search history.
    • Something like this:
      image
  • second iteration: Provide the option to manually save/favorite/star/mark a timefilter for later usage.

    • This should also be exposed via API so other tools like dftimewolf can set prepared timefilters based on information it gets from other places (e.g. a case management tool).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants