-
Notifications
You must be signed in to change notification settings - Fork 408
Open
Labels
bugSomething isn't workingSomething isn't workinglogstashRelating to Malcolm's use of LogstashRelating to Malcolm's use of LogstashpipelineRelating to carving (extraction) of files from traffic and the scanning of those filesRelating to carving (extraction) of files from traffic and the scanning of those files
Milestone
Description
FOR UPLOADED FILES, filescan logs are not tagged with same tags as "source" logs
Steps to reproduce:
- upload
foobar.pcapcontaining some file transfers - filter for
tag:foobar(you'll seezeeklogs, but notfilescanlogs) - remove filter (you'll now see the filescan logs)
For "live" files (captured on Hedgehog, etc.) this should be working correctly. It's only for uploaded ones it's an issue.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workinglogstashRelating to Malcolm's use of LogstashRelating to Malcolm's use of LogstashpipelineRelating to carving (extraction) of files from traffic and the scanning of those filesRelating to carving (extraction) of files from traffic and the scanning of those files
Type
Fields
Give feedbackFrequency
None yet
Projects
Status
Todo (develop)