Project

General

Profile

Actions

Support #1900

closed

Field http.hostname not being parsed out correctly.

Added by Josh Lane over 7 years ago. Updated almost 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

Seeing an issue with Suricata 3.1.1 & 3.1.2 where the HTTP URL, Method, Protocol, etc and all parsed into fields, but the http.hostname field is not parsed. Attached is a sample pcap where this is showing to be repeatable. We are seeing this with the ET Pro ruleset on sig ID 2814364, rev 3. We do see the http information clearly and parsed in other fields like http.http_refer. The packet in the pcap clearly shows the hostname as "Host: ..." which we expect but Suricata isn't parsing out that field. I would assume Suricata has access to the ET Pro rules but if not please let me know. Thanks.


Files

Suricata Hostname Parsing Issue.pcap (16.2 KB) Suricata Hostname Parsing Issue.pcap Example pcap for testing Josh Lane, 09/26/2016 03:05 PM
broken.pcap (21.7 KB) broken.pcap Not parsing out correctly Josh Lane, 10/10/2016 10:57 AM
working.pcap (102 KB) working.pcap Is parsing out correctly Josh Lane, 10/10/2016 10:57 AM
Actions

Also available in: Atom PDF