forked from cisagov/Malcolm
-
Notifications
You must be signed in to change notification settings - Fork 61
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
handle multiple NetBox sites #449
Labels
Milestone
Comments
mmguero
added
capture
Relating to pcap-capture container
enhancement
New feature or request
logstash
Relating to Malcolm's use of Logstash
upload
Relating to PCAP and/or Zeek log ingestion
sensor
For issues dealing with the Hedgehog OS capture sensor
netbox
Related to Malcolm's use of NetBox
labels
Mar 19, 2024
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 11, 2024
…ad and logstash parts are mostly working
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 11, 2024
…ad and logstash parts are mostly working
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 11, 2024
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 12, 2024
…. reworked netbox lookup to be per-site for everything
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 12, 2024
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 12, 2024
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 13, 2024
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 19, 2024
mmguero
added a commit
to mmguero-dev/Malcolm
that referenced
this issue
Jun 19, 2024
This was referenced Jun 26, 2024
Merged
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
NetBox has the concept of sites. Malcolm doesn't handle multiple sites very well (at all, really), it just lets the user provide a
NETBOX_DEFAULT_SITE
value that is checked against tags for upload and used for live capture.We should allow multiple sites, which means we need to provide a way to associate captured data with a particular site. This includes:
NETBOX_DEFAULT_SITE
variable above)This needs to come through for all uploaded data and captured with Zeek and Suricata. We could look at arkime as well although I'm not sure where it would be specified for arkime data. The value is stored today in
source.device.site
andsource.segment.site
anddestination.device.site
anddestination.segment.site
.The text was updated successfully, but these errors were encountered: