Details
-
Improvement
-
Status: Done
-
Major
-
Resolution: Done
-
None
-
None
-
None
Description
Query filtering capabilities were recently added to metron-common and used as part of the threat triage infrastructure. This Jira tracks exposing the PCAP query functionality via the CLI to expose filtering the packet data similar to the existing REST API. This will expose both the legacy ability to filter by src/dest ip/port as well as the new query filtering feature.
Attachments
Issue Links
- is a clone of
-
METRON-155 Expose query filtering capability for PCAP via Metron REST API
- Done
- links to