[DISCUSS] Metron standard field names

2016-09-21 Thread Yohann Lepage
Hi everyone, I wanted to solicit some discussion around Metron standard field names. I would love to have "convenient" field names. As convenient, I mean: short, not ambiguous, well-known, documented. Here is my feeling regarding the actual standard field names[0]: - ip_src_addr: too long, co

Re: [DISCUSS] Metron standard field names

2016-09-21 Thread Yohann Lepage
2016-09-21 22:00 GMT+02:00 zeo...@gmail.com : > Elasticsearch can't use periods in field names, It's possible again since the latest release https://www.elastic.co/blog/elasticsearch-2-4-0-released -- Yohann L.

[DISCUSS] Metron IRC channel

2016-09-29 Thread Yohann Lepage
Hi everyone, There are currently two IRC channels on FreeNode for Metron: - #apache-metron - #apache-metron-dev One channel is maybe enough as we are less than 5 users. What do you think? Which one to keep ? Related issue: https://issues.apache.org/jira/browse/METRON-337 - Invite ASFBot to #apa

Re: Name conventions for parsers

2016-10-06 Thread Yohann Lepage
2016-10-06 12:21 GMT+02:00 zeo...@gmail.com : > I would think that instead we work to make each parser able to handle all > the known outputs (and document explicitly what outputs per parser are > supported) from a product and go back to vendor_product, with versions of > the product supported/test

Build failure - metron_mpack: Assembly is incorrectly configured

2016-10-12 Thread Yohann Lepage
Hi, In my environment, the build on current master fails because is empty in metron-mpack.xml Am I the only one? It could be related to the behavior of maven-assembly-plugin since 2.2 : In previous versions (before 2.2 final), leaving off the assembly id and leaving the classifier unconfigured

Re: Build failure - metron_mpack: Assembly is incorrectly configured

2016-10-13 Thread Yohann Lepage
2016-10-13 15:49 GMT+02:00 David Lyle : > Also works for me, but I think your analysis is correct. Could you open up > a bug jira for a fix? Done: https://issues.apache.org/jira/browse/METRON-500 -- Yohann L.

Re: [ANNOUNCE] Metron Apache Community Demo Recording Oct14,2016

2016-10-15 Thread Yohann Lepage
Hi James, Thanks for the recording! Could you please also update the "Meeting Notes" page on the wiki with the link to the recording? https://cwiki.apache.org/confluence/display/METRON/Meeting+notes Thanks 2016-10-14 21:40 GMT+02:00 James Sirota : > The recording is available at: > https://you

Re: [DISCUSS] Metron IRC channel

2016-11-16 Thread Yohann Lepage
; >> > >> ditto. > >> > >> On Thu, Sep 29, 2016 at 1:29 PM, Casey Stella > wrote: > >> > >> > I'd agree; let's focus on #apache-metron > >> > > >> > On Thu, Sep 29, 2016 at 11:55 AM, James Sirota >