-
Notifications
You must be signed in to change notification settings - Fork 12
Description
brimdata/zui#1593 describes our intent to replace the "a la carte" Brim custom Zeek/Suricata Runner prefs with one that will allow the user to point to a Brimcap config YAML. Since Brimcap is new to these users, I should write an article that describes in brief how they can recreate a YAML config equivalent to what they had before. We can link to the article from the notification that users will see in the app upon upgrade (brimdata/zui#1594), and we can also link to it from next to the Preference setting (similar to what we did before with the "docs" link next to the Zeek Runner pref.)
While I'm at it, I should update the Brim article at https://github.com/brimdata/brim/wiki/Zeek-Customization to emphasize how that's only relevant to releases v0.24.0 and earlier, and similarly reference to the Brimcap doc as the place to learn about the new approach.
Since the config YAML needs to include a shaper, this probably also represents a first pass of coverage for #8.