Squert and Sguil Database and Squert Graph?

123 views
Skip to first unread message

bug...@gmail.com

unread,
Feb 16, 2016, 1:02:09 PM2/16/16
to security-onion
Hi,

I have been using Squert to classify my events, but noticed that when I go to Sguil those events are still there...
I have basically spent the last hour clearing all my events in Squirt but 2 I wanted to investigate... Went to Sguil and ... horror! 3000+ events still there!
I made sure to change the date range in Squert to see all events still left in the queue.

I thought Sguil and Squert were sharing the same Database, am I mistaken?
Have I just forgot to press a magic key in Sguil so my work in Squert gets reflected?

Also, whilst looking for an answer to the above quesitons, I came accross Doug's great series of blog post on Sguil and Squert... it is quite old (from 2011) and in the part 4 there is a great looking graph from Squert, has this option disapeared from the new version?
It looked so cool... kind of Malego :o)

Thanks,
Bugs.

bug...@gmail.com

unread,
Feb 16, 2016, 1:03:01 PM2/16/16
to security-onion

bug...@gmail.com

unread,
Feb 16, 2016, 1:05:45 PM2/16/16
to security-onion
Maybe I am posting those questions too fast :)
I have noticed I didn't go far enough in the Squert timeline, so am working on this now. Sguil might have displayed those older events..
I am still keeping that thread because of the question on the Squert Graph...

Doug Burks

unread,
Feb 16, 2016, 4:39:15 PM2/16/16
to securit...@googlegroups.com
On Tue, Feb 16, 2016 at 1:02 PM, <bug...@gmail.com> wrote:
> Also, whilst looking for an answer to the above quesitons, I came accross Doug's great series of blog post on Sguil and Squert... it is quite old (from 2011) and in the part 4 there is a great looking graph from Squert, has this option disapeared from the new version?
> It looked so cool... kind of Malego :o)

The old visualizations have been totally replaced by the new visualizations.


--
Doug Burks

bug...@gmail.com

unread,
Feb 16, 2016, 5:10:30 PM2/16/16
to security-onion

> The old visualizations have been totally replaced by the new visualizations.

Fair enough, and the new visualizations look much better too! (although I never used the old version) plus I guess that Maltego style graph may have not been too practical... still looked interesting though!

B.

Reply all
Reply to author
Forward
0 new messages