google / timesketch

Collaborative forensic timeline analysis
Apache License 2.0
2.52k stars 577 forks source link

Merge multiple intelligence attributes if present #3113

Closed tomchop closed 5 days ago

tomchop commented 1 week ago

This is a workaround to a strange race condition (https://github.com/google/timesketch/issues/3114) encountered when an analyzer runs on multiple timelines and decides to overwrite a sketch attribute, a situation which the yetiindicators.py analyzer seems to run into fairly often.