Skip to content

Uploaded PCAPs that result in no filename-derived tags will erroneously end up with internal tags on them #774

@mmguero

Description

@mmguero

If you upload PCAP files that don't generate any filename-derived tags in them (e.g., PCAP files that are named with just numbers like 1234.pcap, etc.) the "internal" tags used for things like tracking netbox site ID (e.g., NBSITEID0) and the timestamp (e.g., 1757950840756858) will end up in the tags field.

The filter that does this needs to remove the metadata field holding the tags if there are no user-defined or filename-derived tags.

Metadata

Metadata

Assignees

Labels

bugSomething isn't workinglogstashRelating to Malcolm's use of LogstashuploadRelating to PCAP and/or Zeek log ingestion

Type

Projects

Status

Released

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions