have netbox enrichment mark logs for newly-discovered devices #573
Labels
enhancement
New feature or request
logstash
Relating to Malcolm's use of Logstash
netbox
Related to Malcolm's use of NetBox
Milestone
Prompted by #572
It would be a cool if during population of NetBox inventory via passively-gathered network traffic metadata that the network log entry that results in a newly-created entry in NetBox were somehow marked/flagged as a "new device." This could then be tied into alerting. It would also be a candidate for an event severity scoring category.
Network records marked as such should also probably show up in the "uninventoried devices" visualizations in Asset Interaction Analysis and Zeek Known Summary dashboards.
One question we need to consider: when autopopulation is not enabled, do we still want to set this flag? My guess is probably not, since you'd just re-trigger again and again for the same device? I guess it's a matter of semantics: is this flag meant to mean "new device autopopulated into NetBox inventory" or "uninventoried device observed?"
The text was updated successfully, but these errors were encountered: