Re: New PMC members

2017-12-07 Thread zeo...@gmail.com
Congratulations, guys! Well deserved by all 3. Jon On Thu, Dec 7, 2017 at 10:48 AM Kyle Richardson wrote: > Congratulations guys! Well deserved. > > -Kyle > > On Thu, Dec 7, 2017 at 10:18 AM, Nick Allen wrote: > > > Congrats to all 3 for joining

Re: [MENTORS][DISCUSS] Release Procedure + 'Kafka Plugin for Bro'

2017-12-07 Thread zeo...@gmail.com
zeo...@gmail.com <zeo...@gmail.com> wrote: > Sounds good. Yes Matt, I will handle my parts now. Thanks everyone > > Jon > > On Thu, Dec 7, 2017 at 2:32 PM Matt Foley <ma...@apache.org> wrote: > >> I can start the release process tonight. >> >

Re: [MENTORS][DISCUSS] Release Procedure + 'Kafka Plugin for Bro'

2017-12-07 Thread zeo...@gmail.com
or adjust?" I'm not seeing anything that suggests > anything too terrible, so unless we see some more discussion, I suggest we > move forward with (a). > > > On Mon, Dec 4, 2017 at 9:34 PM, zeo...@gmail.com <zeo...@gmail.com> wrote: > > > I would prefer a, but I wa

Re: [MENTORS][DISCUSS] Release Procedure + 'Kafka Plugin for Bro'

2017-12-04 Thread zeo...@gmail.com
uot;the Apache-way". > > > > In my mind, the best way to accommodate the additional repo, while > minimizing changes to our release management process, is to treat the new > repo as a submodule. I fail to see significant downsides to this approach. > A few extract command

Re: [DISCUSS] Upcoming Release

2017-12-04 Thread zeo...@gmail.com
E > > > > > > > > On Wed, Nov 15, 2017 at 10:04 AM, Nick Allen < > > n...@nickallen.org> wrote: > > > > > Hi Guys - > > > > > > I want to follow-up on this discussion. It sounds like > most &g

Re: [MENTORS][DISCUSS] Release Procedure + 'Kafka Plugin for Bro'

2017-11-27 Thread zeo...@gmail.com
In an attempt to keep this from becoming unbearably long, I will try to keep my responses short, but I would be happy to elaborate. That's a fairly good timeline and summary, but here are some clarifications in corresponding order: - The plugin history is quite short and you can probably get a

Re: [MENTORS][DISCUSS] Release Procedure + 'Kafka Plugin for Bro'

2017-11-27 Thread zeo...@gmail.com
The reason we decided to do that was because it is the best way for it to be used (and thus improved on and quality tested) by the broader bro community. If it's any indication of it's popularity, there was just an email on the bro mailing list about the plugin a few days ago, and I've already

Re: [DISCUSS] NPM / Node Problems

2017-11-27 Thread zeo...@gmail.com
Note that I cleaned up the ansible scripts that install C++ 11 in my latest PR <https://github.com/apache/metron/pull/847/files>, but it's not super relevant to this conversation. Jon On Mon, Nov 27, 2017 at 10:42 AM zeo...@gmail.com <zeo...@gmail.com> wrote: > That was also r

Re: [DISCUSS] NPM / Node Problems

2017-11-27 Thread zeo...@gmail.com
That was also required for bro 2.5.2, so I did that here . Feel free to reuse the approach elsewhere Jon On Mon, Nov 27, 2017 at 10:03 AM Otto Fowler wrote: > First issue is that we need

Re: [MENTORS][DISCUSS] Release Procedure + 'Kafka Plugin for Bro'

2017-11-22 Thread zeo...@gmail.com
e version. This isn’t necessary, but it > makes things easy to keep track of. That still leaves room for necessary > patches on a given release line. > > If you prefer other approaches, please propose. When we reach consensus, > I can edit the Release Process to document it. > Ch

Re: [DISCUSS] Upcoming Release

2017-11-18 Thread zeo...@gmail.com
e cut the release, we can introduce the work for ES 5.x > in > >>METRON-939. I know we will need lots of help testing and reviewing > >> this > >>one. > >> > >> > >> > >>We also have an outstanding question that needs r

master full-dev issues?

2017-11-16 Thread zeo...@gmail.com
Anybody else having issues spinning up full-dev? I'm consistently failing on the Metron Alerts UI install. Spun it up fine yesterday for my other testing. 2017-11-16 17:57:41,772 - Execution of '/usr/bin/yum -d 0 -e 0 -y install metron-common' returned 1. Error: Nothing to do

Re: [MENTORS][DISCUSS] Release Procedure + 'Kafka Plugin for Bro'

2017-11-16 Thread zeo...@gmail.com
I expect a few version changes up front to add some new features to the package (0.1 for the initial release, 0.{2..n} for some new features, 1.0 when we stabilize) but after that it will probably only be updated to follow kafka/librdkafka updates. Jon On Thu, Nov 16, 2017 at 10:10 AM Otto

Re: [DISCUSS] Upcoming Release

2017-11-16 Thread zeo...@gmail.com
lude it in the next release. But I am wary of blocking > the release for that work. No need for you to rush through it. > > Just one man's opinion. Would like to hear feedback from more of the > community. > > > > On Thu, Nov 16, 2017 at 8:01 AM, zeo...@gmail.com <zeo...@gm

Re: [DISCUSS] Release Procedure + 'Kafka Plugin for Bro'

2017-11-16 Thread zeo...@gmail.com
I would suggest that we institute a release procedure for the package itself, but I don't think it necessarily has to line up with metron releases (happy to be persuaded otherwise). Then we can just link metron to metron-bro-plugin-kafka by pointing to specific metron-bro-plugin-kafka releases

Re: [DISCUSS] Upcoming Release

2017-11-16 Thread zeo...@gmail.com
My PR is to turn it into a package containing a plugin* On Thu, Nov 16, 2017, 08:01 zeo...@gmail.com <zeo...@gmail.com> wrote: > The way master's full-dev is set up right now is non optimal for the bro > plugin configuration, and I would like to complete the roadmap I outlined >

Re: [DISCUSS] Upcoming Release

2017-11-16 Thread zeo...@gmail.com
> > > > (8) After we cut the release, we can introduce the work for ES 5.x > in > > METRON-939. I know we will need lots of help testing and reviewing > this > > one. > > > > Please correct me if I am wrong. I will try and send out updates as > we > >

Assign METRON-1307 to Brian Hurley and close

2017-11-14 Thread zeo...@gmail.com
I'm unable to find Brian Hurley in the list of assignees, but he was the one who contributed the fix[1]. Can someone assign and close this JIRA? Thanks, Jon 1: https://github.com/apache/metron/pull/835 -- Jon

Re: Committing to the metron-bro-plugin-kafka repo

2017-11-09 Thread zeo...@gmail.com
On Wed, Nov 8, 2017 at 2:57 PM zeo...@gmail.com <zeo...@gmail.com> wrote: > I'm not strongly against it, but my biggest interest was not wasting time > doing something that will get ripped out fairly quickly. That said, > discussing this is taking more time than doing the work, an

Re: Committing to the metron-bro-plugin-kafka repo

2017-11-08 Thread zeo...@gmail.com
deploys the plugin to Full Dev from the new repository > > What do you think? > > > > On Wed, Nov 8, 2017 at 11:00 AM zeo...@gmail.com <zeo...@gmail.com> wrote: > > > So, here's my argument against the sub-module approach: > > - If we add a sub-module int

Re: Committing to the metron-bro-plugin-kafka repo

2017-11-08 Thread zeo...@gmail.com
* Add a sub-module pointing to the repo and ensure that the Ansible > deployment to Full Dev can deploy Bro with the Kafka plugin > > > > > > On Tue, Nov 7, 2017 at 9:19 AM, zeo...@gmail.com <zeo...@gmail.com> wrote: > > > So here's an update on this, and I'm l

Re: Committing to the metron-bro-plugin-kafka repo

2017-11-07 Thread zeo...@gmail.com
o do before we start accepting enhancements? > > Thanks for the update and all the hard work, Jon. > > On Mon, Nov 6, 2017 at 10:02 PM, zeo...@gmail.com <zeo...@gmail.com> > wrote: > > > Sorry for the delay here - I pushed this out tonight (link > > <https://gi

Re: Committing to the metron-bro-plugin-kafka repo

2017-11-06 Thread zeo...@gmail.com
b.com/JonZeolla/metron-bro-plugin-kafka/pull/1>. Jon On Mon, Sep 18, 2017 at 11:52 AM Nick Allen <n...@nickallen.org> wrote: > Nice! Looks good to me. > > > > > > > On Mon, Sep 18, 2017 at 11:35 AM zeo...@gmail.com <zeo...@gmail.com> > wrote: > &g

Re: [DISCUSS] Upcoming Release

2017-11-06 Thread zeo...@gmail.com
I agree, I think it's very reasonable to move in line with Nick's proposal. I would also suggest that we outline what the target versions would be to add in the METRON-777 components, since it has been functional for a very long time but not reviewed and has some really rockstar improvements.

Re: [DISCUSS] - Remove Kibana

2017-11-01 Thread zeo...@gmail.com
I'm probably okay with marking it as deprecated in two releases (after moving to 5.x, thus not really helping with the migration), but it depends a lot on increased functionality for the metron alerts UI IMO. Jon On Wed, Nov 1, 2017 at 12:51 PM Otto Fowler wrote: > I

Re: [DISCUSS] Release Process Update

2017-10-25 Thread zeo...@gmail.com
om/apache/metron/pull/815 > Rational in > https://issues.apache.org/jira/browse/METRON-1278 > > Thanks, > --Matt > > On 10/24/17, 5:37 AM, "zeo...@gmail.com" <zeo...@gmail.com> wrote: > > Hmm, I kind of like it as a historical validation/confirmation

Re: [DISCUSS] Release Process Update

2017-10-24 Thread zeo...@gmail.com
er fixes to the READMEs to > make > > them > > suitable for site-book. At that point it's just gone entirely. from > > the > > next release. > > > > Doesn't solve the problem of prior releases (assuming we care enough > > to do > > anything

[DISCUSS] Release Process Update

2017-10-23 Thread zeo...@gmail.com
Today I was poking around the Metron site and documentation, and I noticed that the site-book's travis build status image is pointing to master for all of our releases. We should probably update the release process to pin this

Re: new committer: Raghu Mitra

2017-10-20 Thread zeo...@gmail.com
Congratulations, Raghu! Jon On Fri, Oct 20, 2017, 12:11 Simon Elliston Ball wrote: > Congratulations Raghu. Well deserved with all that awesome UI work that’s > coming in. > > Simon > > > On 20 Oct 2017, at 17:10, James Sirota wrote: > > > > >

Re: Suricata parser

2017-10-17 Thread zeo...@gmail.com
I would love to see one, and if it doesn't exist in the next few weeks I'm going to take a stab at it. Jon On Mon, Sep 25, 2017, 09:49 Carolyn Duby wrote: > > Is anyone working on a Suricata parser? > > https://suricata-ids.org/ > > > I was not able to find an

Re: Metron 0.4.2 release date

2017-10-08 Thread zeo...@gmail.com
As of right now I'm not aware of any discussions regarding a next release, and I believe the METRON-777 features are at least a few months out from being reviewed and merged in (There is a fair amount of work in chunking it up to be reviewed, then work to review and merge it in). ES 5.x is also

Re: who is having problems installing?

2017-10-06 Thread zeo...@gmail.com
make them more consumable. The problem > with videos is that they become out of date very quickly and it's a lot of > effort to re-record them. > > Thanks, > James > > 06.10.2017, 11:05, "zeo...@gmail.com" <zeo...@gmail.com>: > > To generalize a bit, I t

Re: Quick Dev

2017-10-06 Thread zeo...@gmail.com
I say we kill it and repoint the site. That will give us one less thing to upgrade to centos 7 as well. Jon On Fri, Oct 6, 2017, 08:27 Justin Leet wrote: > So what are we going to do with Quick Dev? I'm pretty sure everybody's > been using full dev for awhile now (and

Re: SUM aggregator not working?

2017-10-04 Thread zeo...@gmail.com
You're right, with ES 5 we can use periods directly instead of transforming them in indexing to colons (actually, this feature was reintroduced sin 2.4 ). I outlined this as a benefit in the original JIRA

Re: [DISCUSS] Build broken due to transitive dependencies

2017-10-02 Thread zeo...@gmail.com
Hmm, 0.4.1 built fine for me. Jon On Mon, Oct 2, 2017 at 10:44 AM Casey Stella wrote: > Ok, the build is broken in metron-config due to some transitive changes > that happened in npm-land: > > [INFO] > >

Re: [DISCUSS] Community meeting on Tuesday, Sept.23 10AM PST

2017-09-25 Thread zeo...@gmail.com
and are able to arrive to a decision > > Thanks, > James > > 25.09.2017, 08:27, "Otto Fowler" <ottobackwa...@gmail.com>: > > https://youtu.be/-ISycoP3TVA > > > > The video is short and simple. Hopefully it is what you are looking for. > > > &

Re: [DISCUSS] Community meeting on Tuesday, Sept.23 10AM PST

2017-09-21 Thread zeo...@gmail.com
I won't be able to make it and would really like to make sure there's a recording for this one, if possible. I'm unavailable until Thursday of next week, but not necessarily suggesting this gets moved. Jon On Thu, Sep 21, 2017, 15:04 Otto Fowler wrote: > I can’t make

Re: feature branch bumps

2017-09-20 Thread zeo...@gmail.com
But wait, I thought we had established that this was such a fundamental change that it was hard to chunk it out and keep master working. Jon On Wed, Sep 20, 2017 at 3:08 PM Nick Allen wrote: > > Otto: Well, if there is an alternative merge strategy, I’m all ears. > > Yes,

Re: [DISUCUSS] [CALL FOR COMMENT] Metron parsers as actual extensions

2017-09-20 Thread zeo...@gmail.com
Per our prior conversations, I prefer option 2 - treating third party and built-in the same way. I would love to see signing of extensions in the future as a potential follow-on so we could verify the Metron built-ins (and even third parties). Jon On Wed, Sep 20, 2017 at 10:22 AM Otto Fowler

Re: [GitHub] metron issue #760: METRON-1188: Ambari global configuration management broke...

2017-09-19 Thread zeo...@gmail.com
Spun up fine now, thanks. On Tue, Sep 19, 2017, 14:09 mmiklavc wrote: > Github user mmiklavc commented on the issue: > > https://github.com/apache/metron/pull/760 > > A @JonZeolla fixing it now. Sorry about that - I missed one of the > "patch_path -> patch_file"

Re: [ANNOUNCE] Apache Metron Release 0.4.1

2017-09-19 Thread zeo...@gmail.com
Great job everybody, this is a really top notch release. Well done Jon On Tue, Sep 19, 2017, 15:53 Otto Fowler wrote: > Congratulations everyone, great job. Thank you Matt! > > > On September 19, 2017 at 15:22:21, Matt Foley (ma...@apache.org) wrote: > > I’m very

Re: Committing to the metron-bro-plugin-kafka repo

2017-09-15 Thread zeo...@gmail.com
ntain the revision history too. I'm sure > there is a way to do it, but would have to research a bit. Then we apply > your changes on top of that. > > Thanks > > On Thu, Sep 14, 2017 at 1:36 AM, zeo...@gmail.com <zeo...@gmail.com> > wrote: > > > So, I've bee

Committing to the metron-bro-plugin-kafka repo

2017-09-13 Thread zeo...@gmail.com
So, I've been working on METRON-813 lately and I have an initial run at it ready to go here (squashed history, see a better history there

Re: [VOTE] Metron Release Candidate 0.4.1-RC4

2017-09-10 Thread zeo...@gmail.com
+1 (binding) - Verified the signature - Verified all hashes - mvn -q -T 2C surefire:test@unit-tests && mvn -q surefire:test@integration-tests && mvn -q test --projects metron-interface/metron-config && build_utils/verify_licenses.sh - Spun up full-dev - Manually reviewed the site-book. Found

Unclear recent commit

2017-09-08 Thread zeo...@gmail.com
I was looking through some of the recent commits and I noticed this[1], anybody know what the back story is there? 1: https://github.com/apache/metron/commit/c8e84fa3be89901013168d15df38b8a58265148a Jon -- Jon

Re: Ambari Metrics Collector failing...

2017-09-07 Thread zeo...@gmail.com
for 0.4.1? Also, should I create JIRA > ticket? > > On 2017-09-06 16:45, zeo...@gmail.com wrote: > > I'm seeing the same issue right now as well on my fresh bare metal > > install > > of HDP (no Metron yet), haven't dug into it further to troubleshoot. > > > >

Re: Ambari Metrics Collector failing...

2017-09-06 Thread zeo...@gmail.com
I'm seeing the same issue right now as well on my fresh bare metal install of HDP (no Metron yet), haven't dug into it further to troubleshoot. Jon On Wed, Sep 6, 2017, 18:22 Laurens Vets wrote: > In preparation of 0.4.1-rc, I'm trying to install the current github > master

Re: [DISCUSS] Metron release 0.4.1

2017-09-05 Thread zeo...@gmail.com
h > will be included. > > > >Jon and Anand, will they be in by end/day Friday? > >Thanks, > >--Matt > > > >On 8/31/17, 7:45 AM, "Nick Allen" <n...@nickallen.org> wrote: > > > >Matt, et al - For JIRAs that are going into master, sho

Re: [ANNOUNCE] Metron community meeting

2017-09-05 Thread zeo...@gmail.com
Jon, > >> > >>> > >> > >>> Sure. Lets move it by a day. The reason it's at this time is to > >> give > >> > people > >> > >>> in India and Europe a chance to attend live. > >> > >>> > >> >

Re: [DISCUSS] Metron release 0.4.1

2017-09-01 Thread zeo...@gmail.com
et al - For JIRAs that are going into master, should we be > marking > these as "Next + 1" or "0.4.1" ? > > On Thu, Aug 31, 2017 at 8:17 AM zeo...@gmail.com <zeo...@gmail.com> > wrote: > > > Can I advocate to get METRON-1129 in the RC, and thro

Re: [DISCUSS] Metron release 0.4.1

2017-08-31 Thread zeo...@gmail.com
Can I advocate to get METRON-1129 in the RC, and throw in a second vote for METRON-1134? Both in an attempt to better support of prod/offline use. Happy to provide testing cycles for the former. Jon On Wed, Aug 30, 2017 at 11:41 AM Anand Subramanian < asubraman...@hortonworks.com> wrote: > Hi

Re: [DISCUSS] METRON-777 and the road to perditi... er enlightenment

2017-08-23 Thread zeo...@gmail.com
This is all great stuff. As far as feature branch naming, I would suggest something like feature/$brief_explanation accompanied with a feature branch JIRA that explains the original intent of the branch and its goals/"complete" indicators. Along the lines of the FEATURE.md, I feel like at the

Re: [DISCUSS] Synopsis of Community Meeting on 8/22/2017

2017-08-23 Thread zeo...@gmail.com
Was there any discussion about future features of Metron aside from 777/942? In the initial announce thread the agenda mentioned where want to take the project long-term and feature requests and comments on existing features. My thoughts on the topic are that I would like to see a move quickly

Re: [ANNOUNCE] Metron community meeting

2017-08-21 Thread zeo...@gmail.com
assword: biFTEuh2 > > For global callers: > > > https://hortonworks.webex.com/hortonworks/globalcallin.php?serviceType=MC=590161912=1 > > Thanks, > James > > 18.08.2017, 11:02, "zeo...@gmail.com" <zeo...@gmail.com>: > > Is it possible to reschedul

Re: [ANNOUNCE] Metron community meeting

2017-08-18 Thread zeo...@gmail.com
Is it possible to reschedule this to later in the day or another day? That overlaps with the eclipse on the east cost of the US that some people would like to enjoy. Jon On Fri, Aug 18, 2017, 13:48 James Sirota wrote: > I would like to propose a meeting with the following

Re: [Question] Stopping Storm, Metron & Kafka doesn't stop all Storm processes?

2017-08-18 Thread zeo...@gmail.com
leup of messages which Metron > suddenly can't process. > > Any ideas on how to further troubleshoot this? > > On 2017-08-17 11:10, zeo...@gmail.com wrote: > > I used to run into similar issues when my environment was resource > > constrained but never ran it to root cause.

Re: [Question] Stopping Storm, Metron & Kafka doesn't stop all Storm processes?

2017-08-17 Thread zeo...@gmail.com
I used to run into similar issues when my environment was resource constrained but never ran it to root cause. It has been a long time since I was in this scenario to re-test. https://issues.apache.org/jira/projects/METRON/issues/METRON-485 Jon On Thu, Aug 17, 2017 at 12:49 PM Laurens Vets

Re: Upgrade vagrant base to centos 7

2017-08-07 Thread zeo...@gmail.com
//github.com/apache/metron/blob/master/metron-deployment/packaging/packer-build/README.md > . > > -D... > > > On Sun, Aug 6, 2017 at 10:34 AM, Otto Fowler <ottobackwa...@gmail.com> > wrote: > > > https://issues.apache.org/jira/browse/METRON-667 > > > > &g

Re: [DISCUSS] Easing the ramp-up into contributing

2017-07-27 Thread zeo...@gmail.com
I'm totally in agreement here, and I would add to the list the migration from the wiki to the site-book. There were some prior email conversations on this, some of which I started and then didn't follow up on, but I see this as pretty important and I'm still interested in doing the work/helping

Re: [DISCUSS] Relocate Docker

2017-07-13 Thread zeo...@gmail.com
I agree to moving it to a contrib or contrib-like area. Jon On Thu, Jul 13, 2017 at 12:38 PM Kyle Richardson wrote: > I completely support the idea of moving metron-docker down in the tree. I > do like the idea of a contrib/ area for things like this that are not as

Re: [Request for Consensus Approval] dev branch for Stellar additional work

2017-07-05 Thread zeo...@gmail.com
That all sounds pretty reasonable to me. My biggest concern would be attribution during step 5 - we would need to make sure it isn't squash merged like we typically do (assuming we do properly squash merge into the speculative branch). Not a big issue though, I guess, just need to make sure it

Re: [DISCUSS] Mutation of Indexed Data

2017-06-22 Thread zeo...@gmail.com
The key should be a solved problem as of METRON-765 , right? It provides a single key for a given message that globally stored with the message, regardless of where/how. Jon On Thu, Jun 22, 2017 at 9:01 AM Justin

Re: [Discussion] About the wiki….

2017-06-13 Thread zeo...@gmail.com
I suggested in the past and got some buy in, but never had time to move everything into GitHub. I vote to mostly or entirely archive the wiki. Jon On Tue, Jun 13, 2017, 5:19 PM Laurens Vets wrote: > On 2017-06-13 14:09, Otto Fowler wrote: > > I think there are things in the

Re: Installation problem with Docker and processor that does not support virtualization

2017-06-08 Thread zeo...@gmail.com
rds, > > Simone > > > Il 8 giugno 2017 alle 11.37 "zeo...@gmail.com" <zeo...@gmail.com> ha > scritto: > > If I recall properly, 0.3.1 does not require docker yet. That will come > with 0.4.0/master. It still does require virtualization, however, to spin > up

Re: Installation problem with Docker and processor that does not support virtualization

2017-06-07 Thread zeo...@gmail.com
If your processor doesn't support virtualization right now I would suggest looking into if it is simply disabled in your BIOS/UEFI (most processers have supported this for 10+ years, excluding some processors of course). Docker is integrated into the build process right now and is considered

Re: [INCOMING] Metron 0.4.0 release (RC3)

2017-06-01 Thread zeo...@gmail.com
What about 976, which follows the Kerberized trend for this release? Jon On Thu, Jun 1, 2017, 6:03 PM Nick Allen wrote: > Sounds good, Matt. Looking forward to cutting this release. > > On Thu, Jun 1, 2017 at 5:17 PM, Matt Foley wrote: > > > Hi all, > >

METRON-777

2017-05-31 Thread zeo...@gmail.com
I was wondering, is anybody planning to or currently taking a look at Metron 777? I think this is a great contribution and very important to improving the usability of the platform (along with some of it's follow on PRs). I would be happy to help with functional testing and security static code

Re: [DISCUSS] Metron IRC channel

2017-05-24 Thread zeo...@gmail.com
, 2017 at 14:49:32, zeo...@gmail.com (zeo...@gmail.com) wrote: > > Perhaps we could think about adding what I wrote below this to the ticket > > <https://issues.apache.org/jira/browse/INFRA-12931>? Please feel free to > > double check it. Also, if someone is a moderator of

Re: [DISCUSS] Metron IRC channel

2017-05-24 Thread zeo...@gmail.com
JIRA tickets. Finally, can we establish `cstella` as having Level 10 Karma in the config? Thanks. Jon On Tue, May 2, 2017 at 8:54 AM zeo...@gmail.com <zeo...@gmail.com> wrote: > Per the INFRA ticket, perhaps we should reopen and ask for what we > mentioned above? > > Jon

Re: [Discuss] Cyber Security Asset Management for Metron

2017-05-24 Thread zeo...@gmail.com
I would be very interested in a graph db that could leverage the ip_src_addr and ip_dst_addr fields in a broad sense (who is talking to who, visualize top talkers, etc.). In order to be very useful it would need to have the ability to apply filters (IPs, ports, connection durations, bytes

Re: [DISCUSS] Enrichment Split/Join issues

2017-05-16 Thread zeo...@gmail.com
The field stub also gives something that can potentially be used in the error dashboard (or similar) to graph, allowing failed enrichments to "shout" louder to the end user. Jon On Tue, May 16, 2017 at 12:34 PM Nick Allen wrote: > > but also adds a field stub to indicate

Re: we currently have 31 PR’s that are not landed

2017-05-16 Thread zeo...@gmail.com
Assuming the unincubating process is almost completed (I don't know if that's true or not), I think there are some simple, obvious priorities based on our pending 0.4.0 release. Things like METRON-833, METRON-819, and METRON-953 should probably get finalized and merged in asap. Also, we have

Re: integration testing framework

2017-05-15 Thread zeo...@gmail.com
The standard has been centos6 for installing Metron up to this point. There are some Ubuntu guides floating around as well. Jon On Mon, May 15, 2017, 8:07 AM moshe jarusalem wrote: > I would like to ask another question related to this topic. > If I am going to install metron

Infosec training (including Metron)

2017-05-14 Thread zeo...@gmail.com
If anybody is interested, I'll be touching on Metron as a part of some security training I'll be doing as at BSides Pittsburgh 2017 on June 8th (main conference is June 9). It's a whole day of infosec training for only $100, feel free to come check it out! https://www.bsidespgh.com/training/

Re: Why bro parser allows periods in keys?

2017-05-09 Thread zeo...@gmail.com
e should never be any reason to combine ES and HDFS indexing, > unless there is a use case I’m missing... > > Simon > > > > On 9 May 2017, at 15:00, zeo...@gmail.com <zeo...@gmail.com> wrote: > > > > Have we ever considered the use case where we might want to co

Re: Parser Docs

2017-05-08 Thread zeo...@gmail.com
Definitely worthwhile. I discussed something similar (but more general) a little while back here . Totally worth the effort IMO. Jon On Mon, May 8, 2017 at 7:36 PM Casey

Re: [DISCUSS] Update Metron Release Documentation

2017-05-05 Thread zeo...@gmail.com
ical hurdle, > I > think we should do so. > > On Mon, May 1, 2017 at 10:06 AM, zeo...@gmail.com <zeo...@gmail.com> > wrote: > > > Just bringing up this thread again, as we're going to have two books > as of > > the 0.4.0 release. I don't have an

Re: Request double-check on Ambari config logic (ES network_host)

2017-05-03 Thread zeo...@gmail.com
ork.host > with wildcard address. > See next message, item C. Basically, while the wildcard causes ES to > “listen” on all IP addresses, it > only *publishes* one, and on a multi-homed server it can be the wrong > one. I can’t be certain > this causes what you’r

Re: Request double-check on Ambari config logic (ES network_host)

2017-05-02 Thread zeo...@gmail.com
cluster deploy for testing the steps. > I have this issue ( along with the wrong interface name ) and can test > when > you have it. > > An eta would help? > > > On May 2, 2017 at 09:14:10, zeo...@gmail.com (zeo...@gmail.com) wrote: > >

Re: Request double-check on Ambari config logic (ES network_host)

2017-05-02 Thread zeo...@gmail.com
Are you working on this one? The JIRA doesn't look like it's currently assigned. Thanks, Jon On Mon, May 1, 2017 at 6:40 PM Matt Foley wrote: > Ah, I see I mis-read METRON-897, and Nick specifically says > "lo:ipv4","eth0:ipv4" did not work for him, but

Re: [DISCUSS] Metron IRC channel

2017-05-02 Thread zeo...@gmail.com
could think about for the future. > > -Kyle > > On Fri, Dec 16, 2016 at 3:57 PM, Casey Stella <ceste...@gmail.com> wrote: > > > I'll leave this open til monday and update the INFRA jira with the > results. > > > > On Fri, Dec 16, 2016 at 3:46 PM, zeo...@

Re: introduction

2017-05-02 Thread zeo...@gmail.com
Welcome, Christian! Best of luck with everything, feel free to shoot an email or hop on our IRC channel #apache-metron on freenode if you'd like to chat further. Jon On Tue, May 2, 2017 at 7:55 AM Christian Tramnitz wrote: > Hello Metron developers, > > I thought I’d first

Recent commit without JIRA in commit message

2017-04-30 Thread zeo...@gmail.com
It looks like METRON-799 (#518 ) got commit without having the JIRA in the title. Is this enough of

Re: Started the infrastructure requests to move to TLP

2017-04-29 Thread zeo...@gmail.com
Does this officially mean 0.4.0 is on hold until the migration is complete? I assume the vote based on RC2 failed (for more reason than one), but also can we assume that work in progress now is more likely to get into 0.4.0? I would love some more time to QA master as it currently is - which I'm

Re: Ambari Wizard: Repo Tab

2017-04-26 Thread zeo...@gmail.com
I'm also interested to know why that's important at such a small scale. Jon On Wed, Apr 26, 2017, 10:51 AM Otto Fowler wrote: > I am following > > https://community.hortonworks.com/articles/60805/deploying-a-fresh-metron-cluster-using-ambari-serv.html > I DO have

Re: auto-install on bare metal

2017-04-26 Thread zeo...@gmail.com
I can verify that I've used https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=65144361 to install Metron on a bare metal cluster before the docker requirement was imposed. Jon On Wed, Apr 26, 2017 at 9:59 AM Otto Fowler wrote: > Right, I think this : >

Re: [DISCUSS] Regression introduced in Full Dev

2017-04-26 Thread zeo...@gmail.com
Apr 26, 2017 at 7:33 AM, zeo...@gmail.com <zeo...@gmail.com> > wrote: > > > Yeah, I don't see the other thread either. Stuck in the outbox Casey? > > > > Jon > > > > On Wed, Apr 26, 2017, 6:53 AM Otto Fowler <ottobackwa...@gmail.com> > wrote: > > &

Re: Status of METRON-153

2017-04-25 Thread zeo...@gmail.com
Just tagging on here to indicate my interest in this - in order to have someone other than me manage the OSs in my Metron cluster, I must run on RHEL 7. I assume that will be common across many enterprises. Semi-recentlyI took a stab at CentOS 7 support but it was a bit of a rough go and I

Re: So we graduated...

2017-04-20 Thread zeo...@gmail.com
Well done everybody! Congrats Jon On Thu, Apr 20, 2017 at 8:55 PM Matt Foley wrote: > Really exciting! Congrats to the founding team! > --Matt > > > On 4/20/17, 4:02 PM, "Houshang Livian" wrote: > > Congratulations Team. Great work! > > > > >

Re: Failing build

2017-04-19 Thread zeo...@gmail.com
we should correct it. I'll have to think a bit more about how > to fix it and if anyone else wants to take a crack at it, feel free. :) > > On Thu, Apr 6, 2017 at 1:26 PM, zeo...@gmail.com <zeo...@gmail.com> wrote: > > > We appear to have a failed build again: > > >

<    1   2