Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add spicy-ldap package #11

Open
philrz opened this issue Nov 3, 2022 · 1 comment
Open

Add spicy-ldap package #11

philrz opened this issue Nov 3, 2022 · 1 comment

Comments

@philrz
Copy link
Contributor

philrz commented Nov 3, 2022

In a public Slack thread a community user recently inquired about LDAP parsing. I did some searching and learned that https://github.com/zeek/spicy-ldap appears to be the way this is currently done in Zeek. I installed it via zkg in my local Zeek 5.0.2 and it worked fine. Therefore the next time we're assembling an updated Zeek artifact to bundle with Brimcap/Brim (which I expect will become feasible when the new Windows port is complete) we can look at including this package so the parsing will happen by default.

@philrz philrz changed the title Add spicy-ldap Add spicy-ldap package Nov 3, 2022
@philrz
Copy link
Contributor Author

philrz commented Apr 1, 2024

This issue is being transferred to the newer build-zeek repo where we're able to build current Zeek releases and hence potentially take up this work now.

That said, it's also become apparent that Spicy support is not available on Windows Zeek (see zeek/spicy#1053 for instance). We've been hesitant to ship with enhancements that work on some of our supported platforms and not others, so I suspect this issue may continue to languish. Of course, users that need an interim solution might consider a Custom Brimcap Config where they could build their own Zeek with Spicy support and use that instead of the one that ships with Brimcap/Zui.

@philrz philrz transferred this issue from brimdata/zeek Apr 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant