-
Notifications
You must be signed in to change notification settings - Fork 59
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Compare and highlight discrepancies between NetBox inventory and observed network traffic #133
Comments
This DQL query (for Dashboards) could be used to show logs for devices (identified by IP address) in the network without a corresponding entry in netbox:
|
Work is moving forward for this feature. Here are two dashboards that highlight things that are missing from the inventory that are observed in network traffic. You'll notice that the These visualizations give a good indication of hosts and services found in the network that aren't in the inventory. |
Feature-tracking issue dependent on #131
We can cross-check network traffic with NetBox's model to highlight entities (devices and services) observed in network traffic for which there is no corresponding entry in the list of inventoried assets.
Currently this exists in two dashboards:
known_
logs andsoftware
logs to provide a summary of the known devices and services in the network. The Uninventoried Observed Services and Uninventoried Observed Hosts tables show services and hosts (by IP address) that weren't found when searched via the NetBox API.I've also incorporated views for uninventoried hosts and services into Arkime:
The text was updated successfully, but these errors were encountered: