Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Run selected/analyzers from "timesketch importer" #3096

Open
hasamba opened this issue May 19, 2024 · 3 comments
Open

Run selected/analyzers from "timesketch importer" #3096

hasamba opened this issue May 19, 2024 · 3 comments

Comments

@hasamba
Copy link

hasamba commented May 19, 2024

im using a script that creates a plaso file from kape output and upload the output file to timesketch,
it would be very helpful if there will be an argument for timesketch_importer that will auto run selected or all analyzers/tagger after uploads and indexing finishes.

thanks

@jkppr
Copy link
Collaborator

jkppr commented May 20, 2024

Hi @hasamba
We are using dftimewolf for this use-case and its TimesketchExporter module supports triggering Analyzers on the uploaded timelines. For example with the upload_ts recipe.

Adding this feature to the timesketch_importer is not on the road map for now, but something that sounds like a great opportunity for a community contribution. I'm happy to review the PR if anyone wants to take a stab.

@wiredinhp
Copy link

@hasamba @jkppr Hi there ! I am a new contributor to this repository and would love to contribute by solving this issue. Could you please assign this issue to me ?

@jkppr
Copy link
Collaborator

jkppr commented May 23, 2024

Hi @wiredinhp thanks for offering to implement this feature request. I have assigned you the issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants