-
Notifications
You must be signed in to change notification settings - Fork 40
METRON-1866: Improve metron-bro-plugin-kafka documentation #17
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @JonZeolla . This looks really good. Just one suggestion for the end of the bro-pkg instructions.
Installed "bro/apache/metron-bro-plugin-kafka" (master) | ||
Loaded "bro/apache/metron-bro-plugin-kafka" | ||
``` | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think it would be good to add the same sanity check that we have at the end of the manual installation instructions, as the last step here.
[root@localhost ~]# bro -N Apache::Kafka
Apache::Kafka - Writes logs to Kafka (dynamic, version 0.3)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sounds good, added a final step to validate manually. Initially, I left that out since bro-pkg
does a very similar test, among others
README.md
Outdated
* You can also filter IPv6 logs from within your Metron cluster [using Stellar](https://github.com/apache/metron/tree/master/metron-stellar/stellar-common#is_ip). In that case, you wouldn't apply a predicate in your bro configuration, and instead Stellar would filter the logs out before they were processed by the enrichment layer of Metron. | ||
* It is also possible to use the `is_v6_subnet()` bro function in your predicate, as of their [2.5 release](https://www.bro.org/sphinx-git/install/release-notes.html#bro-2-5), however the above example should work on [bro 2.4](https://www.bro.org/sphinx-git/install/release-notes.html#bro-2-4) and newer, which has been the focus of the kafka plugin. | ||
|
||
## Settings | ||
|
||
### `kafka_conf` | ||
### `logs_to_send` |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
ac86aca
to
3313e18
Compare
+1 |
…via jonzeolla) closes apache#17
Contributor Comments
This depends on METRON-1304. Pure documentation change