Jason Ish
Jason Ish
> Hmmm ..not sure what the easiest would be - @jasonish any ideas besides enabling the rule dumping in the alert records ? I don't think there is enough info...
This is a problem I'm not sure how to solve best. If it was encrypted, you would have to enter a password every time you started EveBox which is not...
This installs config files, rather than just their examples. I'm not sure if I want to do that. By installing "examples", we can overwrite them on upgrade so a valid...
I can add a default config file with the correct permissions, but the file has to be blank I think. The examples are not good as a default.
Reports are kind of tricky at this time. Its a mix of JavaScript in the frontend, and Go at the backend. I'm working to migrate them all to Go at...
> Would it be possible to make it so you can archive alert IDs for the entire selected time range and not just the visible events on screen? Yeah, I've...
> Or/also, the ability to whitelist SIDs so evebox won't ever display them. There are a number of SIDs I'm interested in aggregate numbers for, but don't care to see...
> Or/also, the ability to whitelist SIDs so evebox won't ever display them. There are a number of SIDs I'm interested in aggregate numbers for, but don't care to see...
> Would it be possible to make it so you can archive alert IDs for the entire selected time range and not just the visible events on screen? @LaramieSmile Trying...
Yes, I think I'll be adding first class support for dumpy. I once had it, but lost it in the rewrite to angular2. I'm looking at adding a "Flow" panel...