Skip to content
This repository has been archived by the owner on Apr 1, 2024. It is now read-only.

Community ID support #36

Closed
philrz opened this issue Sep 4, 2020 · 1 comment · Fixed by #43
Closed

Community ID support #36

philrz opened this issue Sep 4, 2020 · 1 comment · Fixed by #43
Assignees

Comments

@philrz
Copy link

philrz commented Sep 4, 2020

We'd like to enhance the Zeek artifact that's bundled with Brim to add the Community ID field to conn records. This will allow for joining with other data sources, such as Suricata (brimdata/zed#1211).

@philrz
Copy link
Author

philrz commented Oct 9, 2020

Verified in Brim commit e15e557, which includes bundled Zeek release artifact v3.2.1-brim2.

Per the attached video, now when a pcap is dragged into Brim, the community_id field of the Zeek conn records is populated.

Verify.zip

Thanks @nwt!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants