[Zeek] Request for Feedback - Zeek Process Supervision Model

Seth Hall seth at corelight.com
Fri Mar 22 14:09:48 PDT 2019



On 22 Mar 2019, at 11:11, Mike Dopheide wrote:

> One thing I haven't seen specifically called out yet (perhaps I missed 
> it)
> was making sure we keep the functionality for broctl commands that 
> aren't
> really about managing processes.  Like 'check', 'print', 'diag', etc.  
> I
> could be them being part of a separate tool still, but I find them
> extremely valuable for debugging.

We haven't specified or deeply discussed what some of the extra tooling 
will look like yet, but one goal we have is to simplify everything and 
cut out features that aren't utterly critical or can't be done better by 
other system tools (and obviously watching for community feedback and 
discussion on what stays and goes as we keep moving forward!)

   .Seth

--
Seth Hall * Corelight, Inc * www.corelight.com


More information about the Zeek mailing list