Project

General

Profile

Feature #1007

united output

Added by Victor Julien almost 6 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Unified output for all events and alerts into a single "stream", where the stream can be a file, socket, etc.


Files

enhanced-alerting.rst (2.83 KB) enhanced-alerting.rst RFC sent to ML Eric Leblond, 10/25/2013 05:56 AM

Subtasks

Feature #772: JSON output for alertsClosedTom DeCanioActions
Feature #542: TLS JSON outputClosedTom DeCanioActions

History

#1

Updated by Eric Leblond almost 6 years ago

The logging format can be JSON. It should contains all the information available and be extensible:

  • Output all key values possible
    • base64 encode binary
    • examples
      • all http keywords
      • stream chunk
      • packet
    • Extensibility
      • rule can set key:value
      • luajit export value
      • output matched string in alert
        • optional
        • only if significative value
#2

Updated by Victor Julien almost 6 years ago

  • Status changed from New to Assigned
  • Assignee set to Tom DeCanio
  • Target version set to 2.0rc2
#3

Updated by Eric Leblond almost 6 years ago

Attached file is proposal.

#4

Updated by Victor Julien almost 6 years ago

  • Target version changed from 2.0rc2 to 2.0beta2
#5

Updated by Victor Julien over 5 years ago

  • Target version changed from 2.0beta2 to 2.0rc1
#6

Updated by Victor Julien over 5 years ago

  • Status changed from Assigned to Closed

Also available in: Atom PDF