Phil Hagen

Results 52 issues of Phil Hagen

need a readme on exporting custom dashboards with submission guidelines for GitHub inclusion.

documentation

It was suggested to add a pie chart or other visualization of TCP flags. ![50247284-1515a680-039d-11e9-8a3c-592db549220d](https://user-images.githubusercontent.com/428886/50247541-1eefd780-03a6-11e9-9e80-2954971881c1.png)

I think the field name has changed somehow.

parse out PID, PPID, etc, etc.

does this make the data load faster? benchmark and test

it probably makes sense to add some screenshots to the readme

for any [answer] that is an IP, add to [ips] and grok to [answer_ip] for enrichment? passivedns makes this easy since each answer is its own log entry... may need...

for example, bro logs don't all go into the 'logstash' index... conn* goes into netflow, http* into httpdlog, etc. the script needs to accommodate these scenarios, then use 'logstash' as...

create filter plugin that takes a date and IP, then returns a binary flag on whether the IP was identified as a tor exit node at that time. requires historical...