-
-
Notifications
You must be signed in to change notification settings - Fork 67
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feature: Archive events for time range #51
Comments
Or/also, the ability to whitelist SIDs so evebox won't ever display them. There are a number of SIDs I'm interested in aggregate numbers for, but don't care to see the individual events and just clutter things up. |
Yeah, I've thought about this. Like GMail lets you apply an operation to all matching, even if not displayed on the screen (I feature I use). This shouldn't be too hard so perhaps I'll look sooner than later. |
Yes, this is planned. Its pending me completing PostgreSQL support tho. But the idea would be to auto-archive events matching a filter where the filter is the same aggregation used in the event display (sid, src ip, dest ip). So they would never show up in the inbox, but show up in searches, etc. Auto archiving, muting, not sure what to call it. |
Created a feature for issue for this one: #52 |
@LaramieSmile Trying out a dropdown like this: |
Closing as notfixed due to age. Don't see myself getting around to this. |
Would it be possible to make it so you can archive alert IDs for the entire selected time range and not just the visible events on screen?
The text was updated successfully, but these errors were encountered: