Skip to content

timesketch_importer monitoring files and folders #3629

@cvandeplas

Description

@cvandeplas

Is your feature request related to a problem? Please describe.
A feature we're missing is the ability to continuously monitor for new files and folders, and updated files and ingest them into Timesketch, comparable to what Splunk universal forwarder does.

Describe the solution you'd like
The ability to monitor a folder, and all subfolders for new files, or changed files and ingest the data into timesketch.
The sketch_name and timeline_name may need to be dynamic, for example based on the folder path of the files.

Describe alternatives you've considered

  • timesketch-importer.sh is not an option as
    • it only imports new files, when they are fully there (file close),
    • it doesn't support monitoring changes in files (new entries added).
    • It also relies on filesystem features (inotify) which may not be available with NFS or SMB
    • and requires files to be available on the timesketch instance itself

A draft PR will be raised in a moment to request input on a proposed implementation.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions