[Bro] which kafka plugin to use?

Erich M Nahum nahum at us.ibm.com
Tue Aug 15 08:48:53 PDT 2017


> The original kafka plugin, hosted at https://github.com/bro/bro-plugins
> , is now gone.

D'oh, I now see it is also available in aux/plugins/kafka

> When trying to build from the git tree at https://github.com/g-clef/
> KafkaLogger,
> I get the following build error:
>
> [ 33%] Building CXX object CMakeFiles/Kafka-KafkaWriter.linux-
> x86_64.dir/src/AddingJson.cc.o
> /usr/src/KafkaLogger/src/AddingJson.cc:3:20: fatal error: config.h:
> No such file or directory
> compilation terminated.
> CMakeFiles/Kafka-KafkaWriter.linux-x86_64.dir/build.make:80: recipe
> for target 'CMakeFiles/Kafka-KafkaWriter.linux-x86_64.dir/src/
> AddingJson.cc.o' failed

Perhaps this is useful to Aaron Gee-Clough.  I forgot to mention that
I'm using Ubuntu 16.04 running apt-get upgrade periodically.

> I see there's now a Metro fork of the kafka plugin at
>
>
https://github.com/apache/metron/tree/master/metron-sensors/bro-plugin-kafka

>
> but I am reluctant to try it based on email comments that it is beta.
>
> Any comments/suggestions?

While I can use the version in the bro source, I guess my question still
stands:
what's the long-term outlook for kafka support?

-Erich
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.ICSI.Berkeley.EDU/pipermail/bro/attachments/20170815/d2316812/attachment.html 


More information about the Bro mailing list