Join GitHub today
GitHub is home to over 40 million developers working together to host and review code, manage projects, and build software together.Sign up
Feature Request: Index based on "Community ID" #966
Corelight (the company behind Bro/Zeek) published a project describing a "Community ID" - a separate specification for generating a likely-unique identifier for a network connection. This is implemented for both Bro/Zeek and Suricata. It would be great if moloch also supported the Community ID, so as to ease cross-referencing between Bro logs and Suricata logs with the network traffic indexed by moloch.
For more information, see https://github.com/corelight/community-id-spec and http://icir.org/christian/talks/2018-11-suricon-communityid.pdf
I'm very late to the party here, but wanted to say thanks to everyone for adding this! I've added a link to in the known-implementations section over on the spec page: