Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/500#discussion_r110668381
--- Diff: metron-interface/metron-rest/src/main/scripts/metron-rest ---
@@ -0,0 +1,128 @@
+#!/usr/bin/env bash
+#
+# Licensed
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/500#discussion_r110668033
--- Diff:
metron-deployment/packaging/ambari/metron-mpack/src/main/resources/common-services/METRON/CURRENT/package/scripts/rest_master.py
GitHub user simonellistonball reopened a pull request:
https://github.com/apache/incubator-metron/pull/519
METRON-832 Fixed CEF parser for Palo Alto FITW
## Contributor Comments
This is a minor fix to the pattern based on some data found in the wild.
## Pull
Github user simonellistonball closed the pull request at:
https://github.com/apache/incubator-metron/pull/519
---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so
GitHub user simonellistonball opened a pull request:
https://github.com/apache/incubator-metron/pull/519
METRON-832 Fixed CEF parser for Palo Alto FITW
## Contributor Comments
This is a minor fix to the pattern based on some data found in the wild.
## Pull Request
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/489
+1
Given we've got to the point of essentially minor style points, I would say
this is ready to merge. Any remaining niggles we can handle in follow on PRs to
keep them
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r110106648
--- Diff: metron-interface/metron-config/src/app/app.component.ts ---
@@ -0,0 +1,41 @@
+/**
+ * Licensed to the Apache Software
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r110106592
--- Diff: metron-interface/metron-config/e2e/sensor-list/sensor-list.po.ts
---
@@ -0,0 +1,240 @@
+/**
+ * Licensed to the Apache
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r110106585
--- Diff:
metron-interface/metron-config/e2e/sensor-config-readonly/sensor-config-readonly.po.ts
---
@@ -0,0 +1,125
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r109198964
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.ts
---
@@ -0,0 +1,82
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/489
I completely agree that right now this is too grok specific, but I would
suggest we try and get this PR in, and then handle changes to generalise. That
way we can account
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r109186947
--- Diff:
metron-interface/metron-config/src/app/model/threat-triage-config.ts ---
@@ -0,0 +1,23 @@
+import {RiskLevelRule} from
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r109186782
--- Diff:
metron-interface/metron-config/src/app/model/threat-triage-config.ts ---
@@ -0,0 +1,23 @@
+import {RiskLevelRule} from
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r109185935
--- Diff:
metron-interface/metron-config/src/app/model/parse-message-request.ts ---
@@ -0,0 +1,23 @@
+/**
+ * Licensed
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r108071204
--- Diff: metron-interface/metron-config/src/styles.scss ---
@@ -0,0 +1,739 @@
+/**
+ * Licensed to the Apache Software
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r109168862
--- Diff: metron-interface/metron-config/src/app/login/login.component.html
---
@@ -0,0 +1,31 @@
+
+
+
--- End diff
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r109169645
--- Diff: metron-interface/metron-config/angular-cli.json ---
@@ -0,0 +1,51 @@
+{
+ "project": {
+"versio
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/500#discussion_r109141233
--- Diff:
metron-deployment/packaging/ambari/metron-mpack/src/main/resources/common-services/METRON/CURRENT/package/templates
GitHub user simonellistonball opened a pull request:
https://github.com/apache/incubator-metron/pull/493
METRON-807 Changed resources to use non-relative path
## Contributor Comments
[Please place any comments here. A description of the problem/enhancement,
how to reproduce
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107988742
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-field-schema/sensor-field-schema.component.scss
---
@@ -0,0 +1,168
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107987263
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-field-schema/sensor-field-schema.component.html
---
@@ -0,0 +1,113
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r108007221
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-field-schema/sensor-field-schema.component.spec.ts
---
@@ -0,0 +1,506
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r108012411
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-field-schema/sensor-field-schema.component.spec.ts
---
@@ -0,0 +1,506
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107987434
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-field-schema/sensor-field-schema.component.html
---
@@ -0,0 +1,113
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107953775
--- Diff: metron-interface/metron-config/src/app/login/login.component.html
---
@@ -0,0 +1,31 @@
+
+
+
--- End diff
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107987338
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-field-schema/sensor-field-schema.component.html
---
@@ -0,0 +1,113
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107956884
--- Diff:
metron-interface/metron-config/src/app/login/login.component.spec.ts ---
@@ -0,0 +1,65 @@
+/**
+ * Licensed
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107988671
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-field-schema/sensor-field-schema.component.scss
---
@@ -0,0 +1,168
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107954344
--- Diff: metron-deployment/packaging/docker/rpm-docker/SPECS/metron.spec
---
@@ -313,6 +315,25 @@ This package installs the Metron
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107957813
--- Diff:
metron-interface/metron-config/src/app/model/parse-message-request.ts ---
@@ -0,0 +1,23 @@
+/**
+ * Licensed
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107977492
--- Diff:
metron-interface/metron-config/src/app/model/threat-triage-config.ts ---
@@ -0,0 +1,23 @@
+import {RiskLevelRule} from
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107988841
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-field-schema/sensor-field-schema.component.scss
---
@@ -0,0 +1,168
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107977639
--- Diff: metron-interface/metron-config/src/app/model/topology-status.ts
---
@@ -0,0 +1,26 @@
+/**
+ * Licensed to the Apache
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/488
I agree, let's get this sorted, and then follow up with a general review of
the permissions once we've got the rest of the security pieces in place.
---
If your project is set
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932800
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.ts
---
@@ -0,0 +1,82
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932817
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.ts
---
@@ -0,0 +1,82
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932789
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.spec.ts
---
@@ -0,0 +1,161
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932760
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.html
---
@@ -0,0 +1,107
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932746
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.html
---
@@ -0,0 +1,107
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932680
--- Diff: metron-interface/metron-config/package.json ---
@@ -0,0 +1,65 @@
+{
+ "name": "clitest",
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932702
--- Diff: metron-interface/metron-config/src/app/_main.scss ---
@@ -0,0 +1,113 @@
+/**
+ * Licensed to the Apache Software
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932776
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.spec.ts
---
@@ -0,0 +1,161
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932715
--- Diff: metron-interface/metron-config/src/app/app.component.ts ---
@@ -0,0 +1,41 @@
+/**
+ * Licensed to the Apache Software
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932735
--- Diff: metron-interface/metron-config/src/app/app.component.ts ---
@@ -0,0 +1,41 @@
+/**
+ * Licensed to the Apache Software
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932690
--- Diff: metron-interface/metron-config/scripts/start_management_ui.sh ---
@@ -0,0 +1,27 @@
+#!/bin/bash
+#
+# Licensed
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932655
--- Diff:
metron-interface/metron-config/e2e/sensor-config/sensor-config.po.ts ---
@@ -0,0 +1,243 @@
+/**
+ * Licensed
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932605
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-parser-config-readonly/sensor-parser-config-readonly.component.html
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932661
--- Diff: metron-interface/metron-config/e2e/sensor-list/sensor-list.po.ts
---
@@ -0,0 +1,240 @@
+/**
+ * Licensed to the Apache
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932671
--- Diff: metron-interface/metron-config/e2e/sensor-list/sensor-list.po.ts
---
@@ -0,0 +1,240 @@
+/**
+ * Licensed to the Apache
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932638
--- Diff:
metron-interface/metron-config/e2e/sensor-config-readonly/sensor-config-readonly.po.ts
---
@@ -0,0 +1,125
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932625
--- Diff: metron-interface/metron-config/angular-cli.json ---
@@ -0,0 +1,51 @@
+{
+ "project": {
+"versio
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107932616
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-parser-config-readonly/sensor-parser-config-readonly.component.html
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/489#discussion_r107931875
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-grok/sensor-grok.component.html
---
@@ -0,0 +1,42
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107904482
--- Diff: metron-interface/metron-config/src/app/app.component.ts ---
@@ -0,0 +1,41 @@
+/**
+ * Licensed to the Apache Software
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107892970
--- Diff:
metron-interface/metron-config/e2e/sensor-config-readonly/sensor-config-readonly.po.ts
---
@@ -0,0 +1,125
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107905877
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.spec.ts
---
@@ -0,0 +1,161
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107894517
--- Diff: metron-interface/metron-config/e2e/sensor-list/sensor-list.po.ts
---
@@ -0,0 +1,240 @@
+/**
+ * Licensed to the Apache
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107907080
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.ts
---
@@ -0,0 +1,82
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107719953
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-parser-config-readonly/sensor-parser-config-readonly.component.html
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107894592
--- Diff: metron-interface/metron-config/e2e/sensor-list/sensor-list.po.ts
---
@@ -0,0 +1,240 @@
+/**
+ * Licensed to the Apache
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107902092
--- Diff: metron-interface/metron-config/scripts/start_management_ui.sh ---
@@ -0,0 +1,27 @@
+#!/bin/bash
+#
+# Licensed
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107719782
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-parser-config-readonly/sensor-parser-config-readonly.component.html
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107904759
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.html
---
@@ -0,0 +1,107
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107904887
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.html
---
@@ -0,0 +1,107
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107900720
--- Diff: metron-interface/metron-config/package.json ---
@@ -0,0 +1,65 @@
+{
+ "name": "clitest",
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107905795
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.spec.ts
---
@@ -0,0 +1,161
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107904541
--- Diff: metron-interface/metron-config/src/app/app.component.ts ---
@@ -0,0 +1,41 @@
+/**
+ * Licensed to the Apache Software
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107906446
--- Diff:
metron-interface/metron-config/src/app/general-settings/general-settings.component.ts
---
@@ -0,0 +1,82
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107893194
--- Diff:
metron-interface/metron-config/e2e/sensor-config/sensor-config.po.ts ---
@@ -0,0 +1,243 @@
+/**
+ * Licensed
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107892229
--- Diff: metron-interface/metron-config/angular-cli.json ---
@@ -0,0 +1,51 @@
+{
+ "project": {
+"versio
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/484#discussion_r107719261
--- Diff:
metron-interface/metron-config/src/app/sensors/sensor-grok/sensor-grok.component.html
---
@@ -0,0 +1,42
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/488
Opening this to the hadoop group feels wrong from a security perspective.
That gives all the other hadoop users too much write access to the data store.
A better solution would
GitHub user simonellistonball opened a pull request:
https://github.com/apache/incubator-metron/pull/479
METRON-769 Added syslog prog to ASA patterns and exposed syslog_host and
syslog_prog to output
Passed through syslog_host and syslog_prog to ASA output
## Contributor
Github user simonellistonball closed the pull request at:
https://github.com/apache/incubator-metron/pull/451
---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so
GitHub user simonellistonball reopened a pull request:
https://github.com/apache/incubator-metron/pull/451
METRON-157: Added CEF Parser
There is some discussion of using an external library on the jira ticket
for this issue. The library in question is excellent, and covers the spec
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/451
Kicking travis.
---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/451#discussion_r100941897
--- Diff:
metron-platform/metron-parsers/src/main/java/org/apache/metron/parsers/utils/DateUtils.java
---
@@ -0,0 +1,78
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/451#discussion_r100937396
--- Diff:
metron-platform/metron-parsers/src/main/java/org/apache/metron/parsers/cef/CEFParser.java
---
@@ -0,0 +1,274
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/447
Diagram updated in https://github.com/apache/incubator-metron/pull/452
---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub
GitHub user simonellistonball opened a pull request:
https://github.com/apache/incubator-metron/pull/452
Removed MySQL from Enrichment Diagram
You can merge this pull request into a Git repository by running:
$ git pull https://github.com/simonellistonball/incubator-metron
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/451
Agreed, let's pull the date discussion into a wider forum. Apart from this,
is there anything else you see in this parser specifically to block merging?
---
If your project
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/451
The joys of international date parsing, right? Seems like a the CEF
standard is not the most well read among device vendors. A number of the 'from
the wild' examples we've got
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/451#discussion_r100688919
--- Diff:
metron-platform/metron-parsers/src/main/java/org/apache/metron/parsers/cef/CEFParser.java
---
@@ -0,0 +1,272
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/451
Syslog timestamp capture looks to be locale sensitive here, though all
other date parsing is SimpleDateFormat based, so should be robust to locale. Do
you see this issue
Github user simonellistonball commented on a diff in the pull request:
https://github.com/apache/incubator-metron/pull/451#discussion_r100688850
--- Diff:
metron-platform/metron-parsers/src/test/resources/org/apache/metron/parsers/cef/cyberark.json
---
@@ -0,0 +1,21
Github user simonellistonball commented on the issue:
https://github.com/apache/incubator-metron/pull/451
@kylerichardson no problem at all, would really appreciate it if you could
review, and add anything from any work you have on this.
---
If your project is set up for it, you
GitHub user simonellistonball opened a pull request:
https://github.com/apache/incubator-metron/pull/451
Added CEF Parser
There is some discussion of using an external library on the jira ticket
for this issue. The library in question is excellent, and covers the spec well
87 matches
Mail list logo