10000 improved dumpy integration · Issue #21 · jasonish/evebox · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
improved dumpy integration #21
Open
@inliniac

Description

@inliniac

It would be nice to have a direct link to a dumpy generated pcap, instead of first opening the dumpy web page. Perhaps some sane defaults about the timerange can be used.

Additionally, if flow/netflow records are enabled perhaps it's possible to correlate them with the alert record, and pass the (net)flow start/end times to dumpy as the duration.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      0