evebox
evebox copied to clipboard
Feature: Archive events for time range
Would it be possible to make it so you can archive alert IDs for the entire selected time range and not just the visible events on screen?
Or/also, the ability to whitelist SIDs so evebox won't ever display them. There are a number of SIDs I'm interested in aggregate numbers for, but don't care to see the individual events and just clutter things up.
Would it be possible to make it so you can archive alert IDs for the entire selected time range and not just the visible events on screen?
Yeah, I've thought about this. Like GMail lets you apply an operation to all matching, even if not displayed on the screen (I feature I use). This shouldn't be too hard so perhaps I'll look sooner than later.
Or/also, the ability to whitelist SIDs so evebox won't ever display them. There are a number of SIDs I'm interested in aggregate numbers for, but don't care to see the individual events and just clutter things up.
Yes, this is planned. Its pending me completing PostgreSQL support tho. But the idea would be to auto-archive events matching a filter where the filter is the same aggregation used in the event display (sid, src ip, dest ip). So they would never show up in the inbox, but show up in searches, etc. Auto archiving, muting, not sure what to call it.
Or/also, the ability to whitelist SIDs so evebox won't ever display them. There are a number of SIDs I'm interested in aggregate numbers for, but don't care to see the individual events and just clutter things up. Yes, this is planned. Its pending me completing PostgreSQL support tho. But the idea would be to auto-archive events matching a filter where the filter is the same aggregation used in the event display (sid, src ip, dest ip). So they would never show up in the inbox, but show up in searches, etc. Auto archiving, muting, not sure what to call it.
Created a feature for issue for this one: https://github.com/jasonish/evebox/issues/52
Would it be possible to make it so you can archive alert IDs for the entire selected time range and not just the visible events on screen?
@LaramieSmile Trying out a dropdown like this:
Closing as notfixed due to age. Don't see myself getting around to this.