Support Questions

Find answers, ask questions, and share your expertise

metron pcap query

avatar
Expert Contributor

Hi,

I've noticed in the later releases of Metron, there's a new script pcap_zeppelin_run.sh. Does anyone know the use case of this script? I'm very curious in any pcap development within Metron. From reading the script, it looks like a it wraps around the pcap_query script and it's still in the testing phase? Will we be doing pcap query from zeppelin notebook?

thanks

1 ACCEPTED SOLUTION

avatar
Guru

The intention behind this is very much to move towards PCAP query within zeppelin. This script is effectively a backend to provide access to pcap query via a zeppelin interpreter. If you install the sample zeppelin notebooks you will find one demonstrating the PCAP capabilities.

The notebook is used like this:

60408-pcapzepp.png

View solution in original post

2 REPLIES 2

avatar
Guru

The intention behind this is very much to move towards PCAP query within zeppelin. This script is effectively a backend to provide access to pcap query via a zeppelin interpreter. If you install the sample zeppelin notebooks you will find one demonstrating the PCAP capabilities.

The notebook is used like this:

60408-pcapzepp.png

avatar
Expert Contributor

@Simon Elliston Ball

Wonderful news! Thank you for the snapshot and the information, I was able to run the script, but I need to work on the query syntax. I assume the query syntax is in Stellar.