[jira] [Commented] (METRON-1740) Improve Palo Alto parser to handle CONFIG and SYSTEM syslog messages

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1740?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16592188#comment-16592188 ] ASF GitHub Bot commented on METRON-1740: Github user JonZeolla commented on the issue:

[GitHub] metron issue #1171: METRON-1740 make parser support CONFIG and SYSTEM log ty...

2018-08-24 Thread JonZeolla
Github user JonZeolla commented on the issue: https://github.com/apache/metron/pull/1171 Ok I took a larger sampling and redid my testing. Things still look good at a high level. ``` $ wc -l *csv 1046 config.csv 32424 system.csv 100 threat.csv 5090

[jira] [Created] (METRON-1750) Create Parser for Syslog RFC 5424 Messages

2018-08-24 Thread Otto Fowler (JIRA)
Otto Fowler created METRON-1750: --- Summary: Create Parser for Syslog RFC 5424 Messages Key: METRON-1750 URL: https://issues.apache.org/jira/browse/METRON-1750 Project: Metron Issue Type:

[jira] [Commented] (METRON-1748) Improve Storm Profiler Integration Test

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1748?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16592109#comment-16592109 ] ASF GitHub Bot commented on METRON-1748: Github user nickwallen commented on the issue:

[jira] [Commented] (METRON-1748) Improve Storm Profiler Integration Test

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1748?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16592111#comment-16592111 ] ASF GitHub Bot commented on METRON-1748: GitHub user nickwallen reopened a pull request:

[jira] [Commented] (METRON-1748) Improve Storm Profiler Integration Test

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1748?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16592110#comment-16592110 ] ASF GitHub Bot commented on METRON-1748: Github user nickwallen closed the pull request at:

[GitHub] metron pull request #1174: METRON-1748 Improve Storm Profiler Integration Te...

2018-08-24 Thread nickwallen
GitHub user nickwallen reopened a pull request: https://github.com/apache/metron/pull/1174 METRON-1748 Improve Storm Profiler Integration Test Improved the Storm Profiler integration tests based on improvements I made for the Spark Profiler feature branch. * Validate the

[GitHub] metron issue #1174: METRON-1748 Improve Storm Profiler Integration Test

2018-08-24 Thread nickwallen
Github user nickwallen commented on the issue: https://github.com/apache/metron/pull/1174 The CI build hit what seems to be an unrelated, intermittent test failure. ``` ZKConfigurationsCacheIntegrationTest.validateUpdate:230->lambda$validateUpdate$9:230

[GitHub] metron pull request #1174: METRON-1748 Improve Storm Profiler Integration Te...

2018-08-24 Thread nickwallen
Github user nickwallen closed the pull request at: https://github.com/apache/metron/pull/1174 ---

[jira] [Commented] (METRON-1016) METRON Demo System as separate install option

2018-08-24 Thread Nick Allen (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1016?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16592103#comment-16592103 ] Nick Allen commented on METRON-1016: I am very onboard with the end goal described here.  Great

[jira] [Commented] (METRON-1740) Improve Palo Alto parser to handle CONFIG and SYSTEM syslog messages

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1740?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16592081#comment-16592081 ] ASF GitHub Bot commented on METRON-1740: Github user nickwallen commented on the issue:

[GitHub] metron issue #1171: METRON-1740 make parser support CONFIG and SYSTEM log ty...

2018-08-24 Thread nickwallen
Github user nickwallen commented on the issue: https://github.com/apache/metron/pull/1171 @liuy-tnz Are there any other details that might be useful to throw in a README to help users of the parser? For example, you mention PAN-OS "v6.1, v7.0 or v8.0". Would it be helpful to

[jira] [Commented] (METRON-1740) Improve Palo Alto parser to handle CONFIG and SYSTEM syslog messages

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1740?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16591969#comment-16591969 ] ASF GitHub Bot commented on METRON-1740: Github user liuy-tnz commented on the issue:

[GitHub] metron issue #1171: METRON-1740 make parser support CONFIG and SYSTEM log ty...

2018-08-24 Thread liuy-tnz
Github user liuy-tnz commented on the issue: https://github.com/apache/metron/pull/1171 Thank you for what you have done! There are many ways to collect logs. I haven’t used the Monitor before. As long as they are CSV raw logs separated by “,” I think it would be fine. You

[jira] [Commented] (METRON-1740) Improve Palo Alto parser to handle CONFIG and SYSTEM syslog messages

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1740?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16591937#comment-16591937 ] ASF GitHub Bot commented on METRON-1740: Github user JonZeolla commented on the issue:

[GitHub] metron issue #1171: METRON-1740 make parser support CONFIG and SYSTEM log ty...

2018-08-24 Thread JonZeolla
Github user JonZeolla commented on the issue: https://github.com/apache/metron/pull/1171 I spun up this PR, and threw some logs from my Palo (Monitor > Logs > downloaded the max number of logs that I could from Threat, Traffic, Configuration, and System (CSV format) and put in flat

[jira] [Commented] (METRON-1724) Date/time validation missing in PCAP query

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1724?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16591798#comment-16591798 ] ASF GitHub Bot commented on METRON-1724: Github user merrimanr commented on the issue:

[GitHub] metron issue #1172: METRON-1724: Date/time validation missing in PCAP query

2018-08-24 Thread merrimanr
Github user merrimanr commented on the issue: https://github.com/apache/metron/pull/1172 I verified that bug is fixed now. Nice job +1. ---

[jira] [Commented] (METRON-1724) Date/time validation missing in PCAP query

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1724?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16591751#comment-16591751 ] ASF GitHub Bot commented on METRON-1724: GitHub user tiborm reopened a pull request:

[GitHub] metron pull request #1172: METRON-1724: Date/time validation missing in PCAP...

2018-08-24 Thread tiborm
Github user tiborm closed the pull request at: https://github.com/apache/metron/pull/1172 ---

[GitHub] metron pull request #1172: METRON-1724: Date/time validation missing in PCAP...

2018-08-24 Thread tiborm
GitHub user tiborm reopened a pull request: https://github.com/apache/metron/pull/1172 METRON-1724: Date/time validation missing in PCAP query ## Contributor Comments This PR contains date range validation. We added validation messages with hints also, to help the user correct

[jira] [Commented] (METRON-1724) Date/time validation missing in PCAP query

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1724?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16591750#comment-16591750 ] ASF GitHub Bot commented on METRON-1724: Github user tiborm closed the pull request at:

[jira] [Commented] (METRON-1740) Improve Palo Alto parser to handle CONFIG and SYSTEM syslog messages

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1740?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16591712#comment-16591712 ] ASF GitHub Bot commented on METRON-1740: Github user JonZeolla commented on the issue:

[GitHub] metron issue #1171: METRON-1740 make parser support CONFIG and SYSTEM log ty...

2018-08-24 Thread JonZeolla
Github user JonZeolla commented on the issue: https://github.com/apache/metron/pull/1171 When you say Copy log messages generated by the firewall to the landing Kafka topic producer, are you assuming we export from under Monitor > Logs as CSV? ---

[GitHub] metron issue #1172: METRON-1724: Date/time validation missing in PCAP query

2018-08-24 Thread tiborm
Github user tiborm commented on the issue: https://github.com/apache/metron/pull/1172 @merrimanr Tha bug you find was very interesting. We tried two different approaches to fix, but I think @ruffle1986 solution is more suitable and elegant here. I merged it. Please take a look and

[jira] [Commented] (METRON-1724) Date/time validation missing in PCAP query

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1724?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16591592#comment-16591592 ] ASF GitHub Bot commented on METRON-1724: Github user ruffle1986 commented on the issue:

[GitHub] metron issue #1172: METRON-1724: Date/time validation missing in PCAP query

2018-08-24 Thread ruffle1986
Github user ruffle1986 commented on the issue: https://github.com/apache/metron/pull/1172 It's not just simply about sharing the same validator function. It's more complicated than that. Here's a possible fix for that: https://github.com/tiborm/metron/pull/11 ---

[jira] [Created] (METRON-1749) Update Angular in Management UI

2018-08-24 Thread Shane Ardell (JIRA)
Shane Ardell created METRON-1749: Summary: Update Angular in Management UI Key: METRON-1749 URL: https://issues.apache.org/jira/browse/METRON-1749 Project: Metron Issue Type: Improvement

[jira] [Commented] (METRON-1724) Date/time validation missing in PCAP query

2018-08-24 Thread ASF GitHub Bot (JIRA)
[ https://issues.apache.org/jira/browse/METRON-1724?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16591249#comment-16591249 ] ASF GitHub Bot commented on METRON-1724: Github user ruffle1986 commented on the issue:

[GitHub] metron issue #1172: METRON-1724: Date/time validation missing in PCAP query

2018-08-24 Thread ruffle1986
Github user ruffle1986 commented on the issue: https://github.com/apache/metron/pull/1172 I think the problem is that we use the same validator function for both the start and the end date. So after putting it into an invalid state (step 2), however you add a valid time to