The current path from Zeek log to parquet is, log -> Spark -> Parquet file. This is good/fine... .there may be some improvements/short-path that we might investigate.
1) Hand written 'block' converter
2) Simple 'wrap up' a convenience class that uses Spark internally
3) ???
The current path from Zeek log to parquet is, log -> Spark -> Parquet file. This is good/fine... .there may be some improvements/short-path that we might investigate.
1) Hand written 'block' converter 2) Simple 'wrap up' a convenience class that uses Spark internally 3) ???
log->spark->parquet notebook