2010-09-16 23:21:38 +02:00
|
|
|
======================
|
|
|
|
AVERAGE/HIGH PRIORITY:
|
|
|
|
======================
|
|
|
|
|
|
|
|
- Dynamic k parameter in correlation threshold
|
|
|
|
- Testing more scenarios, making more hyperalert models
|
2010-09-11 12:45:30 +02:00
|
|
|
- Bayesian learning among alerts in alert log
|
2010-09-14 19:24:03 +02:00
|
|
|
- libgc support
|
2010-09-16 23:21:38 +02:00
|
|
|
|
|
|
|
=============
|
|
|
|
LOW PRIORITY:
|
|
|
|
=============
|
2010-09-11 12:45:30 +02:00
|
|
|
|
2010-08-14 14:30:41 +02:00
|
|
|
- Managing clusters for addresses, timestamps (and more?)
|
|
|
|
|
2010-09-16 23:21:38 +02:00
|
|
|
=====
|
|
|
|
DONE:
|
|
|
|
=====
|
|
|
|
|
|
|
|
+ PostgreSQL support
|
|
|
|
+ Regex comp cache
|
|
|
|
+ Managing hyperalert graph connection inside the alert structure itself
|
|
|
|
+ Keeping track of all the streams and alerts even after clustered
|
2010-09-18 16:42:11 +02:00
|
|
|
+ Dynamic cluster_min_size algorithm
|
2010-09-16 23:21:38 +02:00
|
|
|
|