Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

have netbox enrichment mark logs for newly-discovered devices #573

Open
mmguero opened this issue Feb 3, 2025 · 1 comment
Open

have netbox enrichment mark logs for newly-discovered devices #573

mmguero opened this issue Feb 3, 2025 · 1 comment
Labels
enhancement New feature or request logstash Relating to Malcolm's use of Logstash netbox Related to Malcolm's use of NetBox
Milestone

Comments

@mmguero
Copy link
Collaborator

mmguero commented Feb 3, 2025

Prompted by #572

It would be a cool if during population of NetBox inventory via passively-gathered network traffic metadata that the network log entry that results in a newly-created entry in NetBox were somehow marked/flagged as a "new device." This could then be tied into alerting. It would also be a candidate for an event severity scoring category.

Network records marked as such should also probably show up in the "uninventoried devices" visualizations in Asset Interaction Analysis and Zeek Known Summary dashboards.

One question we need to consider: when autopopulation is not enabled, do we still want to set this flag? My guess is probably not, since you'd just re-trigger again and again for the same device? I guess it's a matter of semantics: is this flag meant to mean "new device autopopulated into NetBox inventory" or "uninventoried device observed?"

@mmguero mmguero added enhancement New feature or request logstash Relating to Malcolm's use of Logstash netbox Related to Malcolm's use of NetBox labels Feb 3, 2025
@mmguero mmguero added this to the z.staging milestone Feb 3, 2025
@mmguero mmguero added this to Malcolm Feb 3, 2025
@mmguero mmguero modified the milestones: z.staging, v25.03.0 Feb 3, 2025
@mmguero mmguero moved this to Todo (develop) in Malcolm Feb 3, 2025
@trwagner1
Copy link

What I attempted to do without realzing was send everything to a "default" group.

Yes, it would be cool to have newly created devices as a "new device". I see where you are going with this.

Hmmm. If not base or default and not in inventory, then don't add to inventory? Sorry, that's what I'm thinking out loud as high level.

Yes, I agree Network records marked as such should also probably show up in the "uninventoried devices" visualizations in Asset Interaction Analysis and Zeek Known Summary dashboards.

Wait, shouldn't there be a stop gate?

I guess that's what you are asking. MAC address. Isn't that our base identifier?

If MAC address not observed, would that be a way to do a visualization?

Sorry, I'm thinking out loud.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request logstash Relating to Malcolm's use of Logstash netbox Related to Malcolm's use of NetBox
Projects
Status: Todo (develop)
Development

No branches or pull requests

2 participants