-
Notifications
You must be signed in to change notification settings - Fork 130
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
use zeekrunner scripts and zqd cli option #732
Conversation
3620bb1
to
b654376
Compare
fc695df
to
470f2a3
Compare
The zqd side of this is ready in brimdata/zed#718 , so when this Brim PR is approved, I'll merge the zq PR, then update the zq pointers here and merge. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This passed the Windows integration tests, so I don't have platform concerns. I also verified that locally, zqd and zeek are run like so:
501 82132 82131 0 10:20AM ttys007 0:04.24 /Users/mikeb/git/brim/zdeps/zqd listen -l localhost:9867 -datadir /Users/mikeb/git/brim/run/data/spaces -config /Users/mikeb/git/brim/run/zqd-config.yaml -zeekrunner /Users/mikeb/git/brim/zdeps/zeek/zeekrunner
501 82206 82132 0 10:20AM ttys007 0:17.02 /Users/mikeb/git/brim/zdeps/zeek/bin/zeek -C -r - --exec event zeek_init() { Log::disable_stream(PacketFilter::LOG); Log::disable_stream(LoadedScripts::LOG); } local
This is part of the brimsec/brim repo side work for #731.
Use the
-zeekrunner
cli option to zqd ( brimdata/zed#718 ), defaulting to the value of environment variableBRIM_ZEEK_RUNNER
, else to the zeekrunner included from the zdeps zeek artifact ( brimdata/zeek#23 ).