Open mallorybobalice opened 8 years ago
any ideas?
I presume it's saying 'i don't like the date format' I can't really guarantee that field would have a valid date format but would be happy to drop it. (guess I could also edit it in all the signatures but that's probably less practical)...
grep date cuckoo/data/yara/////* returns a about as many different date formats as signatures
hmmm, is anyone familiar enough with ES to help formulate a put statement to disable the mapping?
https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html
either for signatures.target.file.yara.meta.date or target.file.yara.meta.date. i'm not actually sure of the nesting... but the json doc part is above...
anyone?
i'll dig into the logs to see what else is flagging in the next few days
hi,
I have ES 'searchonly' + mongo for reporting.
I've also added a bit of code to the reporting module at the bottom to add signatures into the search (btw the code that's there probs needs some if checks)
for some tasks I get this: