Change log for siemstress
- Keep database connection between consecutive entries
siemparse
sleeps 0.1 on no line (much less idle CPU usage)- Update column/table names (broke backwards compatibility)
- Update magnitude logic (prioritize severity)
parsed_on
andsource_file
columnsdate_stamp_utc
column- Fractional SQL timestamps (not working with siemquery)
siemmanage
andsiemtrigger
bugs
siemmanage
management tool (clear/import/export)
- Split parser UI from functions
- Split config into 2 files (db, sections)
- Update example rules
- Update helper logic
siemparse
now parses from file or stdin- Example visual rules
- Parse helpers for user-definable extended attributes (json string)
- Example helpers
- Trigger rules with TimeInt of 0 automatically start as oneshot
- Updated magnitude logic
- Default rules output to same table
- siemtrigger table creation bug
- Added
Extended
column to event for extended attributes (JSON string)
- Parsing
- Query module/CLI query tool
- Trigger module/tool
- Config file