@ip: match src_ip or dest_ip, and other fields known to be IP addresses
@earliest:TIMESTAMP
@latest:TIMESTAMP
Feature parity between SQLite and Elasticsearch. This means that
some reports were removed, but should come back for both SQLite and
Elasticsearch: https://github.com/jasonish/evebox/issues/95
[sqlite] Enable event retention by default to a value of 7 days. If
an SQLite database becomes too large, it can be hard to trim back
down to a usable size without significant downtime.
When converting a packet to pcap, use the linktype from the packet info if
available. If not available use ethernet. Fixes the case where the packet is
from nfqueue, where its DLT_RAW.
Unfocus time range selector after a new range is selected allowing keyboard
shortcuts to work again without having to click somewhere in the page.
Fix issue where the input section in the configuration file was
being used even if enabled was set to false. This only happened when
using a configuration file with an input section:
https://github.com/jasonish/evebox/issues/159
Changes
Server: Allow wildcard in input filename to allow the usage of threaded eve
output. For example: /var/log/suricata/eve.*.json.
Agent: Allow multiple input paths to be specified.
New keyboard shortcut, '\' to open time range selector.
Features
New DHCP report that attempts to give you a picture of the devices that have
been assigned an IP(v4) address over the requested period of time.
0.12.0
3 years ago
0.12.0 - 2020-09-25
Changes
Server rewritten in Rust. Ideally this should not be noticed.
Stop tagging events with "archived" and "escalated", and only use
"evebox.archived" and "evebox.escalated". This should not be noticed
as EveBox has been using both tags for a very long.
The Docker image is now based on Alpine Linux. Scratch could be
used, but it would break compatibility with previous images.
Agent: The baheaviour of using the log filename suffixed with ".bookmark
has been removed. The agent will prefer to use the configured bookmark
directory (aka data-directory) instead, or if not set, the current
directory where EveBox is being run from. However, if these deprecated
bookmark filenames exist (like after an upgrade), they will continue
to be used.
The command "esimport" has been renamed to "elastic-import".
Fixes
Fix the index_pattern when adding a template to Elasticsearch with a
non logstash index.