zed

A novel data lake based on super-structured data

BSD-3-CLAUSE License

Stars
1.3K
Committers
19

Bot releases are visible (Hide)

zed - v0.14.0

Published by philrz over 4 years ago

Visit the Brim Download page to find the package for your OS platform.

  • zq: Add support for reading from S3 buckets (#733, #780, #783)
  • zq: Add initial support for reading Parquet files (only via -i parquet, no auto-detection) (#736, #754, #774, #780, #782, #820, #813, #830, #825, #834)
  • zq: Fix an issue with reading/writing recursively-nested NDJSON events (#748)
  • zqd: Begin using a "runner" to invoke Zeek for processing imported pcaps (#718, #788)
  • zq: Fix issues related to reading NDJSON during format detection (#752)
  • zqd: Include stack traces on panic errors (#732)
  • zq: Handle \r\n line endings generated by MinGW (Windows) Zeek (#775)
  • zq: Support scientific notation for integer types (#768)
  • zql: Add cast syntax to expressions (#765, #784)
  • zq: Fix an issue where reads from stdin were described as being from - (#777)
  • zq: Improve an NDJSON parsing error to be more detailed than "bad format" (#776)
  • zjson: Fix an issue with aliases in the zjson writer (#793)
  • zq: Fix an issue where typed JSON reads could panic when a field that was expected to contain an array instead contained a scalar (#799)
  • zq: Fix an issue with ZNG handling of aliases on records (#801)
  • zq: Fix an issue with subnet searches (#807)
  • zapi: Introduce zapi, a simple CLI for interacting with zqd servers (#802, #809, #812)
  • zq: Add arguments to generate CPU/memory profiles (#814)
  • zql: Introduce time conversion functions (#822)
  • zq: Ensure Spaces have non-blank names (#826)
zed - v0.13.1

Published by philrz over 4 years ago

Visit the Brim Download page to find the package for your OS platform.

  • zq: Fix an issue with stream reset that was preventing the pcap button in Brim from activating (#725)
  • zql: Allow multiple fields to be written from put processor (#697)
zed - v0.13.0

Published by philrz over 4 years ago

Visit the Brim Download page to find the package for your OS platform.

  • zqd: Enable time indexing to provide faster query response in narrower time ranges (#647)
  • zql: Make ipv4 subnet bases contain 4 octets to remove ambiguity between fractions & CIDR (#670)
  • zq: Use an external sort for large inputs (removes the 10-million line sort limit) (#527)
  • zq: Fix an issue where duplicate field names could be produced by aggregate functions & group-by (#676)
  • zar: Introduce an experimental prototype for working with archived logs (README) (#700)
  • zq: Support recursive record nesting in Zeek reader/writer (#715)
  • zqd: Zeek log import support needed for Brim (#616, #517, #608, #592, #592, #582, #709)
zed - v0.12.0

Published by philrz over 4 years ago

Visit the Brim Download page to find the package for your OS platform.

  • zql: Introduce =~ and !~ operators in filters for globs, regexps, and matching addresses against subnets (#604, #620)
  • zq: When input auto-detect fails, include each attempted format's error (#616)
  • zng: Binary format is now called "ZNG" and text format is called "TZNG" ("BZNG" has been retired) (#621, #630, #656)
  • zql: cut now has a -c option to show all fields not in the provided list (#639, #655)
  • zq: Make -f zng (binary ZNG) the default zq output format, and introduce -t as shorthand for -f tzng (#654)
zed - v0.11.1

Published by philrz over 4 years ago

  • zqd: Send HTTP status 200 for successful pcap search (#605)
zed - v0.11.0

Published by philrz over 4 years ago

  • zql: Improve string search matching on field names (#570)
  • pcap: Better handling of empty results (#572)
  • zq: Introduce -e flag to allow for continued reads during input errors (#577)
  • pcap: Allow reading of pcap files that have a capture length that exceeds the original length of the packet (#584)
  • zqd: Fix an issue that was causing the histogram to draw incorrectly in Brim app (#602)
zed - v0.10.0

Published by philrz over 4 years ago

  • zql: Let text searches match field names as well as values (#529)
  • zql: Fix an issue where ZQL queries exceeding 255 chars caused a crash (#543)
  • zql: Make searches case-insensitive by default (#536)
  • Fix an issue where the Zeek reader failed to read whitespace from the rightmost column (#552)
zed - v0.9.0

Published by philrz over 4 years ago

  • zql: Emit warnings from put processor (#477)
  • zql: Add string functions (#475)
  • zql: Narrow the use of len() to only sets/vectors, introduce new functions for string length (#485)
  • zql: Add ternary conditional operator (#484)
  • zqd: Add waterfall logger (#492)
  • zqd: Make http shutdown more graceful (#500)
  • zqd: Make space deletion cancel and await other operations (#451)
zed - v0.8.0

Published by alfred-landrum over 4 years ago

  • zql: add the put processor that adds or updates fields using a computed
    expression. (#437)
  • zql: add functions for use with put, like Math.min, Math.max, and others.
    (#453, #459, #461, #472)
  • zq: support reading ndjson with user supplied type information. (#441)
  • Fix an issue reading pcaps with snaplen=0. (#462)
zed - v0.7.0

Published by alfred-landrum over 4 years ago

  • Address ingest issues for packet captures in legacy pcap format.
  • Calculate and respond with packet capture time range at the start of ingest,
    so that Brim can immediately display the space's time range.
zed - v0.6.1

Published by alfred-landrum over 4 years ago

Address an issue ingest packet captures in the legacy pcap format.

zed - v0.6.0

Published by alfred-landrum over 4 years ago

  • zq now displays warnings by default; the "-W" flag is removed, replaced by
    the "-q" for quieting warnings.
  • Update license to reflect new corporate name.
  • Address ingest issues for some pcapng packet captures.
  • Address ingest issues for file or path names that required uri encoding.
zed - v0.5.0

Published by alfred-landrum over 4 years ago

  • Support search queries during pcap ingestion.
  • Improved error reporting in zqd, especially during pcap ingestion.
  • Improved performance of space info api.
  • zqd supports ingesting pcapng formatted packet capture files.
zed - v0.4.2

Published by alfred-landrum over 4 years ago

Point release to provide updated AST parsing.

zed - v0.4.1

Published by alfred-landrum over 4 years ago

Point release to provide an updated zql AST.

zed - v0.4.0

Published by philrz over 4 years ago

v0.4.0

  • zqd adds an endpoint to create a new empty space via post
  • zqd adds an endpoint to post packet captures that are indexed and turned into Zeek logs
zed - v0.3.0

Published by alfred-landrum over 4 years ago

  • zqd adds -datadir flag for space root directory.
  • zqd adds -version flag.
  • Add pcap command to interact with packet capture files.
zed - v0.2.0

Published by alfred-landrum over 4 years ago

  • Per-platform binaries will be available as Github release assets.
  • zql examples under zql/docs are now verified via make test-heavy.
  • Negative integers and floats are accepted in zql expressions.
  • Internal integer types now match the ZNG specification.
  • Fixed comparisons of aliased types.
zed - v0.1.0

Published by alfred-landrum over 4 years ago

  • zq moves from github.com/mccanne/zq to github.com/brimsec/zq.
  • Parser and AST moved to zq repo from github.com/looky-cloud/lookytalk.
  • Query language name changed to ZQL.
  • ZNG specification added.
zed -

Published by aswan almost 5 years ago