Re: Metron STIX/Taxii enrichment

2016-10-03 Thread James Sirota
Which feed are you trying to load? 03.10.2016, 17:25, "Dima Kovalyov" : > I am trying to use STIX Extractor and Taxii Loader to load data in HBase > table for further Threat Intel enrichment in Metron. > > I am using following article that describes required configuration > https://github.com/apac

Podling Report Reminder - October 2016

2016-10-03 Thread johndament
Dear podling, This email was sent by an automated system on behalf of the Apache Incubator PMC. It is an initial reminder to give you plenty of time to prepare your quarterly board report. The board meeting is scheduled for Wed, 19 October 2016, 10:30 am PDT. The report for your podling will form

Metron STIX/Taxii enrichment

2016-10-03 Thread Dima Kovalyov
I am trying to use STIX Extractor and Taxii Loader to load data in HBase table for further Threat Intel enrichment in Metron. I am using following article that describes required configuration https://github.com/apache/incubator-metron/tree/master/metron-platform/metron-data-management However, w

Re: Complete steps to add a new parser

2016-10-03 Thread James Sirota
Thanks for doing the work, Otto. We'll take a look 01.10.2016, 21:00, "Otto Fowler" : > I have been able to add a new parser to the the deployment, and have the > cluster fully deploy successfully. After I was able to push data to kafka > from HDF and get it all indexed. > > Unlike quick dev and

[GitHub] incubator-metron pull request #290: METRON-421 Make Stellar Profiler Client ...

2016-10-03 Thread dlyle65535
Github user dlyle65535 commented on a diff in the pull request: https://github.com/apache/incubator-metron/pull/290#discussion_r81655831 --- Diff: metron-analytics/metron-profiler/src/main/assembly/assembly.xml --- @@ -63,7 +63,7 @@ ${project.basedir}

[GitHub] incubator-metron pull request #290: METRON-421 Make Stellar Profiler Client ...

2016-10-03 Thread nickwallen
GitHub user nickwallen opened a pull request: https://github.com/apache/incubator-metron/pull/290 METRON-421 Make Stellar Profiler Client API Accessible in Parser and Enrichment Topologies [METRON-421](https://issues.apache.org/jira/browse/METRON-421) ### Changes T

Re: [DISCUSS] Active Directory Parser for Metron

2016-10-03 Thread zeo...@gmail.com
+1 in need of. No current effort because it is not our primary kerb realm, but we could use it. On Mon, Oct 3, 2016, 17:18 James Sirota wrote: > I've seen traffic come through about multiple efforts for writing the AD > parser for Metron. I'd like to consolidate these efforts so that we can >

[DISCUSS] Active Directory Parser for Metron

2016-10-03 Thread James Sirota
I've seen traffic come through about multiple efforts for writing the AD parser for Metron. I'd like to consolidate these efforts so that we can come up with a generic parser that is suitable for everyone's needs and that we don't duplicate effort. Please post to this thread if you are working

Re: Pittsburgh PA Meetup

2016-10-03 Thread James Sirota
John, I think this is a great idea. Please do an announce thread a few weeks before the event to remind people. Does anyone else also want to do a Metron meetup in their respective area? The PPMC will support and help with presentations or any technical prep you need to do these events.

Re: [RESULT][VOTE] Releasing Apache Metron 0.2.1BETA-RC2

2016-10-03 Thread James Sirota
The vote has now beed advanced to the incubator general board. 03.10.2016, 14:01, "James Sirota" : > The vote has now closed. The results are: > > Binding Votes: > > +1 [TOTAL BINDING +1 VOTES] = 4 (David Lyle, Casey Stella, James Sirota, Nick > Allen) >  0 [TOTAL BINDING +0/-0 VOTES] = 0 > -1 [T

[RESULT][VOTE] Releasing Apache Metron 0.2.1BETA-RC2

2016-10-03 Thread James Sirota
The vote has now closed. The results are: Binding Votes: +1 [TOTAL BINDING +1 VOTES] = 4 (David Lyle, Casey Stella, James Sirota, Nick Allen) 0 [TOTAL BINDING +0/-0 VOTES] = 0 -1 [TOTAL BINDING -1 VOTES] = 0 The vote passes. The vote will now be advanced to the incubator general board 30.0

Re: [VOTE] Releasing Apache Metron 0.2.1BETA-RC2

2016-10-03 Thread James Sirota
+1 (binding). ran it up in AWS 30.09.2016, 13:07, "Casey Stella" : > +1 (binding) > checksums/gpg checked > mvn runs (with ant and tests) > quick dev runs > > On Fri, Sep 30, 2016 at 1:43 PM, David Lyle wrote: > >>  +1 (binding) >> >>  checksums/gpg - checked >>  Rat Check - passed >>  Integrati

Re: Podling Report Reminder - October 2016

2016-10-03 Thread James Sirota
Metron's report for October 2016 has been filed. Copy of the report is attached below Metron Metron integrates a variety of open source big data technologies in order to offer a centralized tool for security monitoring and analysis. Metron provides capabilities for log aggregation, full pac

[GitHub] incubator-metron pull request #289: METRON-461: Install Metron Data Manageme...

2016-10-03 Thread dlyle65535
GitHub user dlyle65535 opened a pull request: https://github.com/apache/incubator-metron/pull/289 METRON-461: Install Metron Data Management tools We omitted metron-data-management in our first iteration of the MPack. This corrects that. Tested on simulated distributed clus

[GitHub] incubator-metron pull request #288: METRON-480: Kibana 4.5+ Requires http.co...

2016-10-03 Thread dlyle65535
GitHub user dlyle65535 opened a pull request: https://github.com/apache/incubator-metron/pull/288 METRON-480: Kibana 4.5+ Requires http.cors.enabled set to false on ES Tested with simulated Docker cluster. Installed Elasticsearch and Kibana services together post-install and

Pittsburgh PA Meetup

2016-10-03 Thread zeo...@gmail.com
I just wanted to mention to everybody that I'm planning to feature Metron at an InfoSec meetup that I run in Pittsburgh PA. Odds are it will be Q1 of 2017, meaning there will be a presentation on 1/12/17, and a hands on lab on 2/9/17. These events generally start around 7pm and go until 8:30 or 9

Re: [DISCUSS] Dockerize Metron

2016-10-03 Thread Tseytlin, Keren
Really liking this conversation on Docker. One additional feature for Dockerized Metron that would be awesome is if there are some sort of proxy configs/capability set up for those of us who work in corporate settings. Whenever I use Docker at work I run into a nasty bug where if I switch netwo

[GitHub] incubator-metron issue #286: METRON-326 Error Handling in ElasticsearchWrite...

2016-10-03 Thread justinleet
Github user justinleet commented on the issue: https://github.com/apache/incubator-metron/pull/286 Moving everything to `metron-writer` seems to cause random build failures (e.g. the one above), based on how things get spun up. It is not deterministic. I'm going to try using option