You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 4 Next »

Metron Consists of the following modules:

 

Module NameModule DescriptionCurrent VersionDocumentation ReferenceGithub Reference
Metron Streaming - Parser TopologyTopology for normalizing telemetry from native sensor formats to the Metron JSON0.1BETAStreaming 
Metron Streaming - Enrichment/Threat Intel TopologyTopology for enrichment of Metron JSON messages, cross referencing them against threat intel stores, and firing alerts0.1BETAStreaming 
Metron Streaming - PCAP TopologyTopology for streaming network packets into HDFS for use with the PCAP Service0.1BETAPCAP Topology 
Metron PCAP ServiceService for running analytics/filtering on the PCAP files in HDFS put there by the PCAP Topology0.1BETAPCAP Service 
Metron SensorsSensors feeding Metron dashboards and analytics0.1BETASensors 
Metron Data LoadersLoaders for bulk loading enrichment and threat intelligence stores0.1BETAData Loads 
Metron UIMetron SOC Analyst UI0.1BETAUI 
Metron Deployment ScriptsScripts for automating Metron deployments0.1BETADeployment Scripts 
  • No labels