metron-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From FeiChen <>
Subject //pcap issue in OpenSOC project
Date Tue, 19 Apr 2016 06:30:44 GMT
The pictures in the mail have some problem, fix again.
i want get some help about OpenSOC from here.  when i  use the function of pcap in the project
of OpenSoc,  i can not make it work well 
Someone can help me ?
the information below is my issue.
  These days , i have learn more about the OpenSOC and the new concept of the Apache Metron,
but i found the the pcap service could not work well , i run the pcap service in the machine
"java -jar OpenSOC-Pcap_Service-0.6BETA-jar-with-dependencies.jar"  and it start the web service
with a port of 8081 and uri is "/pcapGetter", but when i visit this service with
through the web browser, but it  display nothing. then i try to write it into opensoc-ui
config and try to visit it in the opensoc-ui service,  and the pcap search service not work
still, opensoc-ui config can be seen as below, i have tried to find more  material about it
in github website, but failed, ==!
    Someone can tell me how to run the PCAP service so that i can see the pcap data in opensoc
web ui in right way ?  i have already own the pcap data in hbase  and  index  in ES. Just
want to see the function about it in my environment.
    Some information could be seen as below:

Thanks && Best Regards
Fei Chen

【Pcap in Hbase】
【Pcap In ES】

【opensoc-ui config】
  "auth": true,
  "secret": "b^~BN-IdQ9gdp5sa2K$N=d5DV06eN7Y",
  "elasticsearch": {
    "url": ""
  "ldap": {
    "url": "ldap://",
    "searchBase": "dc=opensoc,dc=dev",
    "searchFilter": "(mail={{username}})",
    "searchAttributes": ["cn", "uid", "mail", "givenName", "sn", "memberOf"],
    "adminDn": "cn=admin,dc=opensoc,dc=dev",
    "adminPassword": "opensoc"
  "pcap": {
    "url": "",
    "mock": false
  "permissions": {
    "pcap": ["cn=investigators,ou=groups,dc=opensoc,dc=dev"]


At 2016-04-19 14:17:04, "James Sirota" <> wrote:

Yeah, we see you

From: 陈飞 <>
Reply-To: "" <>
Date: Monday, April 18, 2016 at 11:16 PM
To: "" <>
Subject: Re:Re: Dev List as Well?

anyone can see me?  just test if it is ok ! thanks!

At 2016-04-17 02:15:46, "James Sirota" <> wrote:

Hi John,

Yeah please subscribe to


From: John Omernik <>
Reply-To: "" <>
Date: Friday, April 15, 2016 at 5:25 PM
To: "" <>
Subject: Dev List as Well?

Is there a dev list one can subscribe to as well? Looking forward to discussions!



View raw message