Closed lucaderi closed 4 weeks ago
Create a ClickHouse table used for
dell.ntop.org :) select ALERT_CATEGORY,ALERTS_MAP,STATUS,ALERT_JSON from flows WHERE STATUS =71 limit 1;
SELECT ALERT_CATEGORY, ALERTS_MAP, STATUS, ALERT_JSON FROM flows WHERE STATUS = 71 LIMIT 1
Query id: 533bf866-9d97-45ef-8d76-8afa113f5ec4
┌─ALERT_CATEGORY─┬─ALERTS_MAP─────────┬─STATUS─┬─ALERT_JSON─────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
STATUS is the flow_alert_id
- mapping host_alert_id into mitre info (scripts/lua/modules/alert_definitions/host/)
These tables are created at (every) startup for both SQLite and ClickHouse.
Verified as fixed
Show mitre classification in alerts and allow to search