Support non-MaxMind mmdb data layouts #3683
Labels
Area: Config
Complexity: Modest
A cup of tea and an evening (or two) with Zeek.
Docs: required
New functionality or behavior that should be covered in our documentation
Implementation: Core
Implementation requires modification of the Zeek core
Implementation: Scripts
Implementation requires Zeek scripting
Type: Enhancement
@philrz reported on Slack that alternative geolocation databases use the MaxMind data format but differ in the yielded data layout, see brimdata/geoip-conn#46 for details (including sample data). For example:
Since we currently hardwire the lookup paths, opening such DBs works, but the result value lookups fail.
We can support this by making those paths configurable (as long as the data still fit the respective records), perhaps with "profiles" for common vendors.
The text was updated successfully, but these errors were encountered: