Project

General

Profile

Feature #258

acknolegment in prewikka

Added by prmarino1-gmail-com - almost 12 years ago. Updated about 3 years ago.

Status:
Closed
Priority:
Normal
Start date:
Due date:
% Done:

0%

Resolution:

Description

currently my operations team made a request to have an acknowledgment option as well ad a delete option in prewikka. there are several ways this could be done one way would be to add a field to the database idmef database which would require modifications to libpreludedb and prelude-XLR as well as prewikka. An other method would be to have a second archive database or set of tables which the alert could be moved too upon acknowledgment this would also have the benefit of reducing the size of the tables containing unacknowledged alerts making the query time shorter. the only difficult part of the second method would be figuring out how to present a view containing both the acknowledged alerts and the unacknowledged alerts.

History

#1 Updated by Yoann VANDOORSELAERE over 10 years ago

  • Project changed from PRELUDE SIEM to Prewikka
  • Category deleted (5)

#2 Updated by Jean-Charles ROGEZ almost 6 years ago

  • Assignee deleted (Yoann VANDOORSELAERE)
  • Target version set to 122

#3 Updated by Thomas ANDREJAK almost 4 years ago

  • Target version changed from 122 to Prelude OSS 3.0.0

#4 Updated by Thomas ANDREJAK over 3 years ago

  • Target version changed from Prelude OSS 3.0.0 to Prelude OSS 3.1.0

#5 Updated by Thomas ANDREJAK about 3 years ago

  • Status changed from New to Closed
  • Assignee set to Thomas ANDREJAK

No activity

Also available in: Atom PDF