Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: Uploading PCAP to Timesketch #928

Open
JakePeralta7 opened this issue Nov 4, 2024 · 2 comments
Open

Feature Request: Uploading PCAP to Timesketch #928

JakePeralta7 opened this issue Nov 4, 2024 · 2 comments

Comments

@JakePeralta7
Copy link

Plaso doesn't parse PCAP files, and I think it can be a very useful processor.

Parsing PCAP files can be easily accomplished using scapy or pyshark.

@ramo-j
Copy link
Collaborator

ramo-j commented Nov 4, 2024

I like the idea, but this feature would probably be better living in timesketch (or indeed plaso.) Have you raised FR's there?

Reason being, there are multiple upload methods to Timesketch, DFTW being only one of them. It would make sense to me that TS does the parsing of the pcap, no matter the upload method.

@JakePeralta7
Copy link
Author

Got it, will try raising the FR in Plaso

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants