Skip to content

Goldmane flows should include the source IP address #10601

Open
@andrenth

Description

@andrenth

It would be exceedingly useful if the Goldmane Flows API included a field for the source IP address in a flow, especially for traffic originating from public networks outside the cluster (for completeness, including the whole IP/port 4-tuple would probably be better).

Expected Behavior

The flows in the Goldmane API should include a source IP address field (and Whisker should have an option to display/filter based on it).

Current Behavior

There is no source IP information available at all.

Context

Identifying illegal or malicious inbound traffic would be made much easier with this feature.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions