Hortonworks Docs
»
Hortonworks Cybersecurity Platform 1.6.0
»
Hortonworks Cybersecurity Platform
Hortonworks Cybersecurity Platform
Also available as:
Introduction to Metron Dashboard
Functionality of Metron Dashboard
Metron Default Dashboard
Events
Enrichment
YAF
Snort
Web Request Header
DNS
Customizing Your Metron Dashboard
Launching the Metron Dashboard
Changing the Metron Dashboard Background Color
Adding a New Data Source
Configuring a New Data Source Index
Reviewing the New Data Source Data
Querying, Filtering, and Visualizing Data
Customizing Your Dashboard
Sharing the Metron Dashboard
Triaging Alerts
Launch the Alerts User Interface
Viewing Alerts
Using the Alerts Table
Configure Table Columns
Configure Table Row Settings
Display Additional Alerts Information
Search Alerts
Filter Alerts
Manage Alert Status
Escalate an Alert
Group Alerts
Create a Meta Alert
Save Your Searches
View Your Recent and Saved Searches
Using PCAP
Capturing pcap Data
Processing pcap Data
View pcap Data
Filtering pcap Data
Fixed Filter Option
Query Filter Option
Porting pcap Data to Another Application
Filtering pcap Data
You can search or filter the pcap data using a command line tool.
Fixed Filter Option
The fixed filter option uses a small set of parameters to query the PCAP data. For example, the filter can specify the IP Source Address (
ip_src_addr
) and the IP Destination Address (
ip_dst_addr
) in the query. The fixed filter option is prescriptive and does not allow a lot of flexibility in the query.
Query Filter Option
The query filter leverages Stellar and allows you to be more flexible as you define the parameters used by the query. This filter option uses a binary regular expression that can be run on the packet payload itself. The query filter option can produce a very large output and create multiple files populating them with the specified number of records and titling them with timestamps.
Parent topic:
Using PCAP
© 2012–2019, Hortonworks, Inc.
Document licensed under the
Creative Commons Attribution ShareAlike 4.0 License
.
Hortonworks.com
|
Documentation
|
Support
|
Community