CESNET / SecurityCloudGUI

1 stars 0 forks source link

Show alerts from nemea in the timeline #28

Closed thorgrin closed 6 years ago

thorgrin commented 6 years ago

It would be really great if the GUI could optionally show Nemea events in the timeline. This is probably a feature that should be added to the LiberouterGUI as it will be easier to follow the event to the appropriate module on click. Would you consider adding such a feature?

nerudaj commented 6 years ago

There was a similar request two years ago, but in the reverse order. LGUI was meant to encourage "drill-down" analysis when you can click on Nemea event and it would take you to the SCGUI, zoomed at the time window of the event.

The hooks for this behaviour are already implemented in SCGUI and I thought they were implemented in Nemea, too. I guess it didn't happen after all.

Implementing it the other way (you can see events from Nemea somewhat highlighted in scgui) would be much harder. This is not viable to do in SCGUIv1. As for SCGUIv2 and Nemea v2, both fully integrated in the the LGUI system, it should be possible to do that.

However, I am no longer a developer of the LGUI system. @rkrejci would know who the new developer is.

thorgrin commented 6 years ago

Ok thanks, I'll add this request to the v2 project.