-
Notifications
You must be signed in to change notification settings - Fork 407
Closed
Closed
Copy link
Labels
arkimeRelating to Malcolm's use of ArkimeRelating to Malcolm's use of ArkimedashboardsRelating to Malcolm's OpenSearch Dashboards interfaceRelating to Malcolm's OpenSearch Dashboards interfaceenhancementNew feature or requestNew feature or requestexternalDepends on a bug or feature external to this projectDepends on a bug or feature external to this projectintelRelated to integration with threat intel feedsRelated to integration with threat intel feedslogstashRelating to Malcolm's use of LogstashRelating to Malcolm's use of LogstashzeekRelating to Malcolm's use of ZeekRelating to Malcolm's use of Zeek
Milestone
Description
We could be getting more useful information from our zeek intelligence matches, and this plugin can help us do that
- add plugin to list of plugins to install
- add new fields to intel.log parsing
Splitting this into two parts, one to get the plugin integrated and the basics listed above, and another one at a future time to further expand the usage of these new fields, see #695
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
arkimeRelating to Malcolm's use of ArkimeRelating to Malcolm's use of ArkimedashboardsRelating to Malcolm's OpenSearch Dashboards interfaceRelating to Malcolm's OpenSearch Dashboards interfaceenhancementNew feature or requestNew feature or requestexternalDepends on a bug or feature external to this projectDepends on a bug or feature external to this projectintelRelated to integration with threat intel feedsRelated to integration with threat intel feedslogstashRelating to Malcolm's use of LogstashRelating to Malcolm's use of LogstashzeekRelating to Malcolm's use of ZeekRelating to Malcolm's use of Zeek
Type
Projects
Status
Released