-
Notifications
You must be signed in to change notification settings - Fork 296
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
JSON structure of events: malware.hash #732
Labels
Milestone
Comments
sebix
added
bug
Indicates an unexpected problem or unintended behavior
data-format
labels
Oct 11, 2016
Thanks for reporting this. I think you are correct. When this issue is fixed, migrations of the eventDB might become necessary. |
@dmth is it ok for you guys if we fix this in the next days or is there any current compatibility issue? |
---
Mobile
On 29 Dec 2016, at 10:20, SyNchroAcK ***@***.***> wrote:
@dmth is it ok for you guys if we fix this in the next days or is there any current compatibility issue?
Well we do have some deployments out there and they will all need to migrate the eventDB database structure.
So yes , IMHO it would be fair to first announce this in the users mailinglist.
… —
You are receiving this because you were assigned.
Reply to this email directly, view it on GitHub, or mute the thread.
|
Email sent. Will wait for feedback and then we will proceed with the fix. |
related to #394 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
In the IntelMQ the event object (
etc/harmonization.conf
) mostly looks like a JSON object. For exampleclassification.identifier
,classification.taxonomy
,destination.abuse_contact
,destination.geolocation.cc
etc., can be represented as:.. and so on.
But there is one field, called
malware.hash
, which is a string technically and an object logically at the same time:If someone will want to convert the whole event to the multilevel JSON object - he will fail because of this one field.
Could you replace
malware.hash
withmalware.hash.other
(if hash type is unknown) for example? Other name is acceptable.On the one hand probably many Parsers will have to be updated, but on the other hand you will get a beautiful and correct JSON object.
The text was updated successfully, but these errors were encountered: