Skip to content

have netbox enrichment mark logs for newly-discovered devices #573

@mmguero

Description

Prompted by #572

It would be a cool if during population of NetBox inventory via passively-gathered network traffic metadata that the network log entry that results in a newly-created entry in NetBox were somehow marked/flagged as a "new device." This could then be tied into alerting. It would also be a candidate for an event severity scoring category.

Network records marked as such should also probably show up in the "uninventoried devices" visualizations in Asset Interaction Analysis and Zeek Known Summary dashboards.

One question we need to consider: when autopopulation is not enabled, do we still want to set this flag? My guess is probably not, since you'd just re-trigger again and again for the same device? I guess it's a matter of semantics: is this flag meant to mean "new device autopopulated into NetBox inventory" or "uninventoried device observed?"

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestlogstashRelating to Malcolm's use of LogstashnetboxRelated to Malcolm's use of NetBox

    Projects

    • Status

      Todo (develop)

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions