Re: new committer: Otto Fowler

2016-10-18 Thread Michael Miklavcic
Welcome Otto! On Mon, Oct 17, 2016 at 3:17 PM, Otto Fowler wrote: > Thank you everyone, happy to pitch in. > > On October 17, 2016 at 13:31:13, James Sirota (jsir...@apache.org) wrote: > > The Podling Project Management Committee (PPMC) for Apache Metron > (Incubating) > has asked Otto Fowler to

[GitHub] incubator-metron pull request #308: Metron-498 Grok patterns are now read fr...

2016-10-18 Thread merrimanr
Github user merrimanr commented on a diff in the pull request: https://github.com/apache/incubator-metron/pull/308#discussion_r83879366 --- Diff: metron-platform/metron-parsers/src/main/java/org/apache/metron/parsers/bolt/ParserBolt.java --- @@ -116,6 +122,9 @@ public void execute

[GitHub] incubator-metron issue #310: METRON-495: Upgrade Storm to 1.0.x

2016-10-18 Thread ottobackwards
Github user ottobackwards commented on the issue: https://github.com/apache/incubator-metron/pull/310 Justin - I have added your repo as a remote, checked out and branched storm-1.0 - when I do mvn test - it runs is actually working. Is there a different way to see t

[GitHub] incubator-metron pull request #276: METRON-363 Fix Cisco ASA Parser

2016-10-18 Thread kylerichardson
Github user kylerichardson closed the pull request at: https://github.com/apache/incubator-metron/pull/276 --- If your project is set up for it, you can reply to this email and have your reply appear on GitHub as well. If your project does not have this feature enabled and wishes so, or if t

[GitHub] incubator-metron pull request #276: METRON-363 Fix Cisco ASA Parser

2016-10-18 Thread kylerichardson
GitHub user kylerichardson reopened a pull request: https://github.com/apache/incubator-metron/pull/276 METRON-363 Fix Cisco ASA Parser I've rewritten the ASA parser which can be extended, as needed, to new ASA message types by editing the bundled asa patterns file and the static ma

[GitHub] incubator-metron issue #310: METRON-495: Upgrade Storm to 1.0.x

2016-10-18 Thread ottobackwards
Github user ottobackwards commented on the issue: https://github.com/apache/incubator-metron/pull/310 I just did two mvn integration-test runs back to back. First run : parsers failed Second run: parsers passed, metron-pcap-backend failed --- If your project is set

Re: [jira] [Comment Edited] (METRON-507) Elasticsearch is incorrectly indexing the Bro DNS "answers" field

2016-10-18 Thread James Sirota
Try now On 10/18/16, 12:12 PM, "Jon Zeolla (JIRA)" wrote: > >[ > https://issues.apache.org/jira/browse/METRON-507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15586376#comment-15586376 > ] > >Jon Zeolla edited comment on METRON-507 at 10/18/16

Re: [jira] [Comment Edited] (METRON-507) Elasticsearch is incorrectly indexing the Bro DNS "answers" field

2016-10-18 Thread zeo...@gmail.com
Thanks James, now I can self-assign. I will close 507 and work on 508 soon. Thanks, Jon On Tue, Oct 18, 2016 at 3:15 PM James Sirota wrote: > Try now > > > > > On 10/18/16, 12:12 PM, "Jon Zeolla (JIRA)" wrote: > > > > >[ > https://issues.apache.org/jira/browse/METRON-507?page=com.atlassi

[GitHub] incubator-metron pull request #308: Metron-498 Grok patterns are now read fr...

2016-10-18 Thread mattf-horton
Github user mattf-horton commented on a diff in the pull request: https://github.com/apache/incubator-metron/pull/308#discussion_r83980978 --- Diff: metron-platform/metron-parsers/src/main/java/org/apache/metron/parsers/bolt/ParserBolt.java --- @@ -181,7 +185,8 @@ public void decl

[GitHub] incubator-metron issue #308: Metron-498 Grok patterns are now read from zook...

2016-10-18 Thread mattf-horton
Github user mattf-horton commented on the issue: https://github.com/apache/incubator-metron/pull/308 And one last, doubtless unwelcome :-) thought -- You mentioned regarding line 68 in GrokParser (referring to parserConfig.get("timestampField")), that the timestampField is in the

[GitHub] incubator-metron pull request #308: Metron-498 Grok patterns are now read fr...

2016-10-18 Thread merrimanr
Github user merrimanr commented on a diff in the pull request: https://github.com/apache/incubator-metron/pull/308#discussion_r83984954 --- Diff: metron-platform/metron-parsers/src/main/java/org/apache/metron/parsers/bolt/ParserBolt.java --- @@ -181,7 +185,8 @@ public void declare

[GitHub] incubator-metron issue #308: Metron-498 Grok patterns are now read from zook...

2016-10-18 Thread merrimanr
Github user merrimanr commented on the issue: https://github.com/apache/incubator-metron/pull/308 No problem, that's a good question. The "timestampField" property only changes when you change it in Zookeeper by uploading a config. Let's say we're parsing a sensor and the parsed mes