Support Questions

Find answers, ask questions, and share your expertise
Check out our newest addition to the community, the Cloudera Data Analytics (CDA) group hub.

How to extend Java codes in Snort topology?

We are using Snort to send network packets to Apache Metron, and we want to calculate the average delay between packets (do a statistical analysis). Our solution is to write a java program by changing existing Snort topology inside Apache Storm (we want to make the least changes inside prepared java codes by Metron's team). First of all, is it a right solution?!

Currently, we are able to send packets via Nifi Site-to-Site from a remote machine to the Metron server and see the results in Elasticsearch. To do the job, which file(s) in Metron should be changed, and where should I save the output(s), HDFS for instance?

In the second step, we need to consider windowing to calculate the average value in specific periods. Any advice would be appreciated.


Take a Tour of the Community
Don't have an account?
Your experience may be limited. Sign in to explore more.