Skip to content

Conversation

@AlyaGomaa
Copy link
Collaborator

Closes #1738

  • use processes instead of threads for true parallelism of profiler workers
  • increase workers as throughput increases by checking the input.py and profiler.py flows/sec imbalance

AlyaGomaa and others added 19 commits November 26, 2025 13:22
- Add comprehensive dataset documentation with two workflows:
  - Summarization workflow (event summaries and behavior analysis)
  - Risk analysis workflow (root cause and risk assessment)
- Add detailed workflow implementation guides for both pipelines
- Add LLM evaluation framework and results documentation
- Add DAG parser technical reference documentation
- Organize all documentation under new "Datasets & LLM Training" section in Immune.md
- Fix broken cross-references between documentation files
- Preserve legacy documentation for historical reference
- Create 'Security & Network Configuration' section for ARP and traffic routing docs
- These were incorrectly nested under 'Datasets & LLM Training' section
… before Datasets

- Security & Network Configuration section now appears before Datasets & LLM Training
- This provides better logical flow in the documentation navigation
…file in redis since it's no longer used in slips
…shmap to be able to access their dports later by the portscan modules
…le to import it anywhere (in the db and in the modules that may need it)
…redis channel (new_zeek_fields_line) the recognized indices so other profiler workers know about it
…' line processors from the db instead of the channel because msgs published in that channel won't be accessible by the new worker
…r_module to slips_utils to be used by all modules
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

3 participants