Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

where has the DFIQ questions gone? #3258

Open
hasamba opened this issue Jan 9, 2025 · 7 comments
Open

where has the DFIQ questions gone? #3258

hasamba opened this issue Jan 9, 2025 · 7 comments
Assignees
Labels

Comments

@hasamba
Copy link

hasamba commented Jan 9, 2025

i enabled DFIQ in the settings,
i cloned the DFIQ repo to /etc/timesketch/dfiq/
but still cannot see any questions...i used to in earlier versions
what am i missing?
Image

@jkppr
Copy link
Collaborator

jkppr commented Jan 15, 2025

The whole DFIQ feature is still experimental in Timesketch, sorry.

We moved to DFIQ 1.1 in #3163 to keep support with the Yeti project. But looks like the DFIQ project was not updated yet... I have opened google/dfiq#28 to get this sorted.

For a short term solution you have two options:

@hasamba
Copy link
Author

hasamba commented Jan 15, 2025

So from now on i will have to use Yeti server in order to use or export DFIQ?

@tomchop
Copy link
Collaborator

tomchop commented Jan 17, 2025

@hasamba no, you can still use DFIQ in Timesketch without having to setup a Yeti server. We have google/dfiq#26 which we'll merge ASAP.

@tomchop
Copy link
Collaborator

tomchop commented Jan 17, 2025

It's been merged! @jkppr I don't know what's left to enable this on the TS side.

@jkppr
Copy link
Collaborator

jkppr commented Jan 17, 2025

There should be no additional steps for Timesketch. Just move the v1.1 DFIQ content into the data/dfiq/ folder and ensure the feature is enabled in the timesketch.conf.

@hasamba let us know if it works with the updated version.

@hasamba
Copy link
Author

hasamba commented Jan 21, 2025

i upgraded the db & timesketch docker,
cloned dfiq v1.0.1 (tried also with 1.0.0),
copied data/* timesketch/etc/timesketch/dfiq/
tried also data/* timesketch/etc/timesketch/dfiq/data

all options did not work...

@jkppr
Copy link
Collaborator

jkppr commented Jan 23, 2025

Are you running a dev container or the latest release?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants