Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pivoting Between Data Sources #432

Open
mmguero opened this issue Nov 5, 2024 · 0 comments
Open

Pivoting Between Data Sources #432

mmguero opened this issue Nov 5, 2024 · 0 comments
Labels
arkime Relating to Malcolm's use of Arkime dashboards Relating to Malcolm's OpenSearch Dashboards interface train-operation Training topic related to how to use Malcolm to conduct network traffic analysis training Related to developing and releasing Malcolm training

Comments

@mmguero
Copy link
Collaborator

mmguero commented Nov 5, 2024

@mmguero cloned issue idaholab/Malcolm#365 on 2024-01-15:

For what topic would you like to see training developed?

Illustrate how to use fields like event.id (Zeek's UID and FUID) and Community ID to pivot between dashboards and between Dashboards and Arkime.

What format would be best suited for this training?

A video

Is there existing Malcolm documentation that could be improved by including this topic?

Correlating Zeek logs and Arkime Sessions

@mmguero mmguero added arkime Relating to Malcolm's use of Arkime dashboards Relating to Malcolm's OpenSearch Dashboards interface train-operation Training topic related to how to use Malcolm to conduct network traffic analysis training Related to developing and releasing Malcolm training labels Nov 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
arkime Relating to Malcolm's use of Arkime dashboards Relating to Malcolm's OpenSearch Dashboards interface train-operation Training topic related to how to use Malcolm to conduct network traffic analysis training Related to developing and releasing Malcolm training
Projects
Status: No status
Development

No branches or pull requests

1 participant