Re: errors

2016-07-13 Thread zeo...@gmail.com
> > > [image: cid:image001.png@01D1DCF2.1EC10E60] > > > > *From:* zeo...@gmail.com [mailto:zeo...@gmail.com] > *Sent:* Wednesday, July 13, 2016 10:33 AM > > > *To:* user@metron.incubator.apache.org > *Subject:* Re: errors > > > > That is unreadable for me

Re: Self-introduction

2016-07-21 Thread zeo...@gmail.com
Hi Shigenobu, Welcome to the community. :) Jon On Thu, Jul 21, 2016, 14:23 Shigenobu Koufugata < shigenobu.koufug...@gmail.com> wrote: > Hello, > > I live in Japan. > Recently, I am working for a security consulting firm, which called > nanaroq.com. > This firm has several clients which has

Re: errors

2016-07-12 Thread zeo...@gmail.com
< tejaswi.palacha...@sstech.us> wrote: > Vmware workstation 12. Can u give me the steps if possible? > > > > *From:* zeo...@gmail.com [mailto:zeo...@gmail.com] > *Sent:* Tuesday, July 12, 2016 10:57 AM > > > *To:* user@metron.incubator.apache.org > *Subject:* Re: errors >

Re: failed grok parser metron squid

2017-02-13 Thread zeo...@gmail.com
Evidently I made up 0.2.2 - that was never a release - sorry about that, I guess that was the one we bumped to 0.3.0. Regardless, 0.2.1 is over 4 months old, and thus very different from the current state of the project. Jon On Mon, Feb 13, 2017 at 10:36 PM zeo...@gmail.com <zeo...@gmail.

Re: failed grok parser metron squid

2017-02-13 Thread zeo...@gmail.com
3, 2017 at 6:08 PM zeo...@gmail.com <zeo...@gmail.com> wrote: > > Did you check the permissions on the file are correct? > > > > On Mon, Feb 13, 2017, 5:59 AM tkg_cangkul <yuza.ras...@gmail.com> wrote: > > > > > > > >

Re: no data emitted on metron topology

2017-02-10 Thread zeo...@gmail.com
. > > I'm using ansible installation with metron_install.yml config > > I also use an existing ambari managed hdp. So i install the ambari > separated with metron. > > Any suggestion? > > Thanks > On Feb 10, 2017 6:28 PM, "zeo...@gmail.com" <zeo...@gmail.

Re: BUILD FAILURE

2016-08-25 Thread zeo...@gmail.com
Did you install the JDK as opposed to the JRE? There's some helpful information here - https://community.hortonworks.com/articles/24818/metron-tech-preview-1-install-instructions-on-sing.html - although it's not perfect if you're going to setup from master. Jon On Thu, Aug 25, 2016, 06:45 Kevin

Re: Problem with using metron

2016-10-08 Thread zeo...@gmail.com
hen I open Ambari (link) this is link opens: > http://www.node1.com/ > and metron and services links don't work (or they're not work for me!!!) > > Bita > > On Sat, Oct 8, 2016 at 3:52 PM, zeo...@gmail.com <zeo...@gmail.com> wrote: > > Hello Bita, welcome! > > At t

Re: Problem with using metron

2016-10-09 Thread zeo...@gmail.com
mbari (link) this is link opens: > http://www.node1.com/ > and metron and services links don't work (or they're not work for me!!!) > > Bita > > On Sat, Oct 8, 2016 at 3:52 PM, zeo...@gmail.com <zeo...@gmail.com> wrote: > > Hello Bita, welcome! > > At that poi

Re: Problem with using metron

2016-10-09 Thread zeo...@gmail.com
2:08 PM, zeo...@gmail.com <zeo...@gmail.com> wrote: It looks like you may be running 0.1, can you try using 0.2.1? Jon On Sun, Oct 9, 2016, 00:52 نوشین سادات طاهری <taheri.nooshinsa...@gmail.com> wrote: yeah... sort of!!! I surf the net for my problems...about 2-3 days but I couldn't find

Re: [DISCUSS] METRON-433: Documentation update

2016-09-20 Thread zeo...@gmail.com
Do you think it would be worthwhile to revise the enrichment and parser illustrations to use storm component symbols instead of generic symbols? That may add additional clarity to people who aren't familiar with all of the different components and how they work together. Still running through the

Pittsburgh PA Meetup

2016-10-03 Thread zeo...@gmail.com
I just wanted to mention to everybody that I'm planning to feature Metron at an InfoSec meetup that I run in Pittsburgh PA. Odds are it will be Q1 of 2017, meaning there will be a presentation on 1/12/17, and a hands on lab on 2/9/17. These events generally start around 7pm and go until 8:30 or

Re:

2016-11-30 Thread zeo...@gmail.com
nstallation without > opening any other links or searching for commands, step by step. > Thank you. > > p.s. feel free to let me know if you will encounter any errors as I've > seen them bunch. > > - Dima > > > > On 11/30/2016 04:45 PM, zeo...@gmail.com wrote: > >

Re: How to use Snort and Bro with with Metron (0.2Beta)

2017-03-28 Thread zeo...@gmail.com
arr...@gmail.com> wrote: I have setup it via Code Plateform Vagrant Machine, it is working there. I just need to know how can I use it ? Any small example or usecase will do ? Li On Tue, Mar 28, 2017 at 3:18 PM, zeo...@gmail.com <zeo...@gmail.com> wrote: Do you already have bro and/or snor

Re: How to use Snort and Bro with with Metron (0.2Beta)

2017-03-28 Thread zeo...@gmail.com
you're seeing? Jon On Tue, Mar 28, 2017, 2:27 AM Farrukh Naveed Anjum <anjum.farr...@gmail.com> wrote: > Hi, > 0.3.1 is having problem getting up started. please guide me on Bro and > Snot logs > > On Tue, Mar 28, 2017 at 6:51 AM, zeo...@gmail.com <zeo...@gmail.com> >

Re: tuning indexing metron

2017-03-29 Thread zeo...@gmail.com
s running on it. i'm afraid it will be crash if i set it to > 50% of my RAM. Are ES heap ideally set to 50% RAM memory to get the maximum > performance? > > > On 29/03/17 17:18, zeo...@gmail.com wrote: > > Right off the bat I would give 31GB heap to each ES node. Normally you

Re: using kafka topic with more than 1 partition.

2017-03-27 Thread zeo...@gmail.com
Can you clarify what you mean by recreate your kafka topics? Usually what I do to add partitions to a kafka topic in Metron is something like: zk=server1:2181;/usr/hdp/2.5.0.0-1245/kafka/bin/kafka-topics.sh --zookeeper $zk --alter --topic bro --partitions 4 Once you run this, your bro topic (or

Re: How to use Snort and Bro with with Metron (0.2Beta)

2017-03-27 Thread zeo...@gmail.com
Hi Farrukh, Sorry I'm just now seeing your message. Were you able to get things figured out? Off the bat, I would recommend using 0.3.1 instead of 0.2.0BETA as there are a lot of improvements, but I could definitely help out regarding ingesting Bro and/or Snort logs into Metron. Let me know -

Re: Requirements/performance

2017-03-20 Thread zeo...@gmail.com
I have been doing a lot of hardware+Metron work lately as I prepare to buy my prod hardware, I would be happy to work with you on things. Once my build is in production I will publish statistics regarding my environment. For some very brief mobile friendly metrics, I ingest about 25,000 events

Re: a proper entry level documentation

2017-03-05 Thread zeo...@gmail.com
What OS are you trying with now? Like I mentioned, the scripts I put together before will do Mac and centos 6 but it should be possible to get working on more than that. Your choice, but regardless I plan to work further on documentation. If there's anything specific you'd like addressed or

Re: a proper entry level documentation

2017-03-05 Thread zeo...@gmail.com
I totally agree and I would be happy to help. For setup specifically, should we prioritize a certain OS? To date the focus has mostly been macOS. In order to help my personal development process, I scripted the install process