-
Notifications
You must be signed in to change notification settings - Fork 636
Open
Description
Is your feature request related to a problem? Please describe.
A feature we're missing is the ability to continuously monitor for new files and folders, and updated files and ingest them into Timesketch, comparable to what Splunk universal forwarder does.
Describe the solution you'd like
The ability to monitor a folder, and all subfolders for new files, or changed files and ingest the data into timesketch.
The sketch_name and timeline_name may need to be dynamic, for example based on the folder path of the files.
Describe alternatives you've considered
- timesketch-importer.sh is not an option as
- it only imports new files, when they are fully there (file close),
- it doesn't support monitoring changes in files (new entries added).
- It also relies on filesystem features (inotify) which may not be available with NFS or SMB
- and requires files to be available on the timesketch instance itself
A draft PR will be raised in a moment to request input on a proposed implementation.
Metadata
Metadata
Assignees
Labels
No labels