You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
mmguero opened this issue
Mar 19, 2024
· 0 comments
Assignees
Labels
captureRelating to pcap-capture containerenhancementNew feature or requestlogstashRelating to Malcolm's use of LogstashnetboxRelated to Malcolm's use of NetBoxsensorFor issues dealing with the Hedgehog OS capture sensoruploadRelating to PCAP and/or Zeek log ingestion
NetBox has the concept of sites. Malcolm doesn't handle multiple sites very well (at all, really), it just lets the user provide a NETBOX_DEFAULT_SITE value that is checked against tags for upload and used for live capture.
We should allow multiple sites, which means we need to provide a way to associate captured data with a particular site. This includes:
uploaded pcap: the upload interface should allow the user to specify a site name to associate with files uploaded in a batch of PCAP files
hedgehog linux: when setting up capture hedgehog should allow the user to specify a site name
malcolm live capture: when capturing from local network interfaces we should allow Malcolm to specify a site (this might be the NETBOX_DEFAULT_SITE variable above)
This needs to come through for all uploaded data and captured with Zeek and Suricata. We could look at arkime as well although I'm not sure where it would be specified for arkime data. The value is stored today in source.device.site and source.segment.site and destination.device.site and destination.segment.site.
The text was updated successfully, but these errors were encountered:
mmguero
added
capture
Relating to pcap-capture container
enhancement
New feature or request
logstash
Relating to Malcolm's use of Logstash
upload
Relating to PCAP and/or Zeek log ingestion
sensor
For issues dealing with the Hedgehog OS capture sensor
netbox
Related to Malcolm's use of NetBox
labels
Mar 19, 2024
captureRelating to pcap-capture containerenhancementNew feature or requestlogstashRelating to Malcolm's use of LogstashnetboxRelated to Malcolm's use of NetBoxsensorFor issues dealing with the Hedgehog OS capture sensoruploadRelating to PCAP and/or Zeek log ingestion
NetBox has the concept of sites. Malcolm doesn't handle multiple sites very well (at all, really), it just lets the user provide a
NETBOX_DEFAULT_SITE
value that is checked against tags for upload and used for live capture.We should allow multiple sites, which means we need to provide a way to associate captured data with a particular site. This includes:
NETBOX_DEFAULT_SITE
variable above)This needs to come through for all uploaded data and captured with Zeek and Suricata. We could look at arkime as well although I'm not sure where it would be specified for arkime data. The value is stored today in
source.device.site
andsource.segment.site
anddestination.device.site
anddestination.segment.site
.The text was updated successfully, but these errors were encountered: