Hello Metron

2016-09-21 Thread Otto Fowler
Hi everyone, My name is Otto Fowler, and I work at Leidos Cyber ( formerly Lockheed Martin IS&GS ). I am very impressed with the Metron project and the work everyone has been doing and I’ve really enjoyed working with Metron so far in my evaluation. I look forward to participating in this new bu

Re: Hello Metron

2016-09-21 Thread Casey Stella
Welcome to Metron, Otto. We look forward to your contributions! I'd love to hear your impressions about the good and the bad so far, if you wouldn't mind sharing. If you see any big gaps or any avenues that you think we should dive into, I'd love to hear it. Best, Casey On Wed, Sep 21, 2016 a

Re: [DISCUSS] Ambari Integration

2016-09-21 Thread Justin Leet
Hi all, I opened up a PR at https://github.com/apache/incubator-metron/pull/266 for everyone to take a look at and comment on. For reference, the original JIRA is https://issues.apache.org/jira/browse/METRON-427 It pretty much covers the MVP that Casey outlined and should give a pretty good st

Re: [DISCUSS] Ambari Integration

2016-09-21 Thread Otto Fowler
Hi Justin, Are you testing this against the small_cluster configuration? With the full install ( install ambari etc ) as well as the AWS install? The AWS install seems like it’s own path, and is essentially different from small_cluster. I myself am interested in the whole boat deployment - where

Re: [DISCUSS] Ambari Integration

2016-09-21 Thread Justin Leet
Hi Otto, Couple things to dig into a bit. Let me know if I stray off what your question is, but I think this should give you the answer. For the mpack, it's just taking a cluster without Metron and turning it into a cluster running Metron (regardless of the cluster itself was provisioned). I wa

Re: [DISCUSS] Ambari Integration

2016-09-21 Thread Otto Fowler
Thanks Justin, So this should just replace what is currently happening if you do the full deployment, but you have not tested it as such? I think the difference in the ASW deployment that I saw was how it set the nodes to roles through the script. Sorry if I overstated it. On September 21, 2016

Re: [DISCUSS] Ambari Integration

2016-09-21 Thread Justin Leet
We could definitely replace some of it, but have not replaced anything for this PR. Most changes in the PR are in metron-deployment/packaging/ambari/ + some light surrounding work to make some stuff available that wasn't. The Ansible stuff is basically untouched if not actually untouched. Actually

Re: log parsers-

2016-09-21 Thread Satish Abburi
All, I have put together few interesting log sources what we are looking and also mapped the existing Metron-JIRA#¹s for few of them. https://drive.google.com/open?id=0B3HLRtVIDxauS3E3dE9mb1R3M2M Also, attached same to the email. Thanks, Satish On 9/14/16, 4:09 PM, "Satish Abburi" wrote: >