Feature Request: Uploading PCAP to Timesketch
Opened this issue · 2 comments
JakePeralta7 commented
Plaso doesn't parse PCAP files, and I think it can be a very useful processor.
Parsing PCAP files can be easily accomplished using scapy or pyshark.
ramo-j commented
I like the idea, but this feature would probably be better living in timesketch (or indeed plaso.) Have you raised FR's there?
Reason being, there are multiple upload methods to Timesketch, DFTW being only one of them. It would make sense to me that TS does the parsing of the pcap, no matter the upload method.
JakePeralta7 commented
Got it, will try raising the FR in Plaso