Skip to content

@mwullink mwullink released this Jul 29, 2019 · 11 commits to master since this release

This is the first stable release of ENTRADA 2.x with the following new features

  • ENTRADA 2.0.3 is 2x faster as the previous version and requires less memory. This is possible by only partially parsing and decoding packets. Only those parts of a packet that are required are read from the pcap-file and loaded into memory.
  • Automatically deleting old archived pcap-files if they are older than x days.

Bugs fixed (helped by Sebastian from NZRS):

  • DNS label compression can lead to out-of-memory exception
  • TCP decoding, not always correctly decoding TCP-streams

Deploy ENTRADA using Docker, the image can be found on Docker Hub.
See the WIKI for upgrade/installation details.

Assets 2

@mwullink mwullink released this Jul 23, 2019 · 23 commits to master since this release

This is a major new release

  • Refactored code
  • Based on Spring Boot
  • Added support for Amazon S3 and Athena
  • Added TCP RTT columns
  • Deployment using Docker

See the WIKI for upgrade/installation details.

Assets 2

@mwullink mwullink released this Apr 25, 2019 · 120 commits to master since this release

This release contains a fix for handling invalid pcap files, these files caused entrada to stop processing.
This has been changed in this version, invalid pcap files will now be ignored.

#87 Handle invalid pcap files

Assets 3
Pre-release

@mwullink mwullink released this Mar 22, 2019 · 66 commits to entrada_aws since this release

Do not use this release for production.

Assets 3

@mwullink mwullink released this Mar 20, 2019 · 124 commits to master since this release

This release contains a fix for compressed label decoding and a new feature that will allow ENTRADA to continue processing pcap files even if Hadoop is now available.

This release contains a contribution of the Swedish Internet Foundation IIS (https://internetstiftelsen.se/)

#80 Removed unused code
#81 Fix archiving to work across disks
#82 Error decoding edns0 DNSSECOption
#83 Crashed thread causes ENTRADA to hang forever
#84 Update older (insecure) libraries

Assets 3

@mwullink mwullink released this Mar 8, 2019 · 134 commits to master since this release

This release contains a fix for compressed label decoding and a new feature that will allow ENTRADA to continue processing pcap files even if Hadoop is now available.

This release contains a contribution of DNS Belgium (https://www.dnsbelgium.be)

Features

#77 Convert pcap data when hdfs not availble

Fix

#79 Fix for name compression
#76 Improve IP address decoding

Assets 3

@mwullink mwullink released this Nov 7, 2018 · 150 commits to master since this release

This release contains a fix for a IP addresses decoding problem and 2 new features.

Update

#71 Limit number of simultaneous name server data conversion processes
#75 Add check to see if "move pcap" script is already running

Fix

#74 Fix EDNS-Client-Subnet IP address decoding bug

Assets 3
Pre-release

@mwullink mwullink released this Oct 26, 2018 · 156 commits to master since this release

Updates

#68 EOL for Maxmind legacy geolite databases enhancement

Bug Fixes

#70 Errror cleaning archive when lots of pcaps files present bug
#72 Decode exception: ArrayIndexOutOfBoundsException bug

Assets 3

@mwullink mwullink released this Jan 18, 2018 · 164 commits to master since this release

New features

#60 Google Public DNS: Using dig in place of HTML crawler
#67 Allow for uncompressed pcap files

Bug Fixes

#56 DNSKEY records with ECDSA throw RuntimeException
#61 OpenDNS resolver loading fails
#62 Failing to load pcap with hyphen in the name
#63 Copy script fails if no tmp dir found

Assets 3
Jan 18, 2018
added support for uncompressed
You can’t perform that action at this time.