XMLWordPrintableJSON

Details

    • New Feature
    • Status: Done
    • Major
    • Resolution: Done
    • None
    • 0.6.0
    • None

    Description

      Legacy OpenSOC included a panel in Kibana that allowed users to query for pcap data.  We would like to add this feature back into Metron.  There are 2 discussions happening on the dev list where we are gathering user requirements:

      http://mail-archives.apache.org/mod_mbox/metron-dev/201805.mbox/%3CCAEVkqPYxfe3Q65mX7Mkuk_FKUCV420yb6hcLmf+FF=1OZERFoQ@mail.gmail.com%3E

      and working through the backend architecture:

      http://mail-archives.apache.org/mod_mbox/metron-dev/201805.mbox/%3CCAEVkqPbxzJNU_WGRbFWnZ-MVqnKb7mthEdvEQ9PLYhwfiT7F0g@mail.gmail.com%3E

       Forthcoming sub tasks will be based on the outcome of these discussions.

      Attachments

        1.
        Update REST to run YARN and MR jobs Sub-task Done Ryan Merriman
        2.
        PcapJob should be asynchronous Sub-task Done Michael Miklavcic
        3.
        Enable paging through Pcap result sets Sub-task Done Michael Miklavcic
        4.
        Update MPack to support Pcap panel Sub-task Done Ryan Merriman
        5.
        Enable Kerberos in REST for YARN and MR jobs Sub-task Done Ryan Merriman
        6.
        Create job status abstraction Sub-task Done Michael Miklavcic
        7.
        Retrieve Pcap results in pdml format Sub-task Done Ryan Merriman
        8.
        Create Pcap Query Filter endpoint Sub-task Done Ryan Merriman
        9.
        Create PCAP UI Sub-task Done Tibor Meller
        10.
        Create REST endpoint for job status abstraction Sub-task Done Ryan Merriman
        11.
        PCAP UI - Downloading PCAP page files Sub-task Done Tibor Meller
        12.
        PCAP UI - Introduce the paging capability Sub-task Done Shane Ardell
        13.
        PCAP UI - Add data range selector to the filter bar Sub-task Done Tibor Meller
        14.
        PCAP UI - Fix the download progress bar Sub-task Done Shane Ardell
        15.
        Retrieve Pcap results in raw binary format Sub-task Done Ryan Merriman
        16.
        Create stop job endpoint for Pcap queries Sub-task Done Michael Miklavcic
        17.
        Add more context to PcapJob JobStatus Sub-task Done Michael Miklavcic
        18.
        REST should limit the number of Pcap jobs a user can submit Sub-task Done Ryan Merriman
        19.
        Fix Pcap CLI local FS finalizer Sub-task Done Michael Miklavcic
        20.
        Create REST endpoint to get job configuration Sub-task Done Ryan Merriman
        21.
        Reload a running job in the UI Sub-task Done Ryan Merriman
        22.
        PCAP UI - Input validation Sub-task Done Tibor Meller
        23.
        PCAP UI - Add a way to kill a pcap job Sub-task Done Tibor Meller
        24.
        Add tests to handle different input parameter values Sub-task Done Ryan Merriman
        25.
        Better error messages when there are no results or wireshark is not installed Sub-task Done Ryan Merriman
        26.
        New default input path is wrong in pcap CLI Sub-task Done Ryan Merriman
        27.
        PcapCLI should print progress to stdout Sub-task Done Ryan Merriman
        28.
        PCAP UI - Unable to select/copy from packets details in PCAP query panel Sub-task Done Shane Ardell
        29.
        Add ability to specify YARN queue for pcap jobs Sub-task Done Ryan Merriman
        30.
        Refactor PcapTopologyIntegrationTest Sub-task Done Michael Miklavcic
        31.
        Handle null values in config in Pcap backend more gracefully Sub-task Done Michael Miklavcic
        32.
        PCAP - Escape colons in output dir names Sub-task Done Michael Miklavcic
        33.
        Enable Pcap jobs to be submitted asynchronously Sub-task Done Michael Miklavcic
        34.
        Fix job status liveness bug and parallelize finalizer file writing Sub-task Done Michael Miklavcic
        35.
        PCAP UI - PCAP queries don't work on Safari Sub-task Done Shane Ardell
        36.
        Src and Dst port filters are incorrect after changing to empty Sub-task Done Ryan Merriman
        37.
        Empty print status option causes NPE Sub-task Done Ryan Merriman
        38.
        Document Job cleanup Sub-task Done Ryan Merriman
        39.
        Pcap parser fails to write pacap sequence file to hdfs on kerberized cluster Sub-task Done Mohan Venkateshaiah
        40.
        Pcap directories should have correct permissions Sub-task Done Ryan Merriman
        41.
        UDP packets are not handled Sub-task Done Ryan Merriman

        Activity

          People

            rmerriman Ryan Merriman
            rmerriman Ryan Merriman
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: