-
-
Notifications
You must be signed in to change notification settings - Fork 8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Lite logging #28
Comments
Hi, I am so sorry, I missed your message! BTW - default capture format is since some time PCAP, which is faster compared to smcap. I need to update docs! |
Can you send me more info or a doc link regarding KB knowledge base? My requirements are fairly flexible. |
KB is a new feature not in docs yet, it is just being developed. KB is supposed to log interesting L7 information into an internal tree followint:
Tree can be dumped into JSON file by command, or by the scheduler. The tree is limited in number of tree nodes at a time, fresh nodes are kept, old are removed. In current devel version (pre Currently, it looks as follows:
The plan is:
JSON is not great for appending to existing files, one must read it, parse it, add new data into the three and write again. If you look for more continuous data to, say, |
Yes, CSV would work. https://questdb.io/docs/guides/importing-data/ |
refactor flow queue 2be39fb - prerequisite for large flows |
Let me know when this is ready to test and I'll be happy to help |
I read https://smithproxy.readthedocs.io/en/latest/capture-traffic/ regarding the default smcap logging. Is there a "lite" option for just timestamp, source, and URL? Perhaps in JSON format for easy querying.
The text was updated successfully, but these errors were encountered: