Project

General

Profile

Actions

Feature #1950

open
DH CT

allow configuration of file-store types

Feature #1950: allow configuration of file-store types

Added by Duane Howard over 9 years ago. Updated over 2 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

files-json.log seems to get pretty big pretty quickly. It would be nice to be able to configure which types of files it will log. Alternately being able to only log the metadata for stuff with a filestore rule could be useful.


Related issues 2 (2 open0 closed)

Related to Suricata - Feature #1005: conditional logging: controlling what gets loggedAssignedVictor JulienActions
Related to Suricata - Feature #2055: Optionally logging on files.json - Not log every file, only certain files that are stored and extractedNewOISF DevActions

VJ Updated by Victor Julien about 9 years ago Actions #1

I could imagine 2 types of solutions here:

  1. add some kind of output filtering to the logger (e.g. pattern/regex match)
  2. allow rules to control such logging.

Personally I would prefer the latter although it's a more invasive change.

CK Updated by chris K. about 9 years ago Actions #2

I noticed this issue with the eve-log also. Enabling file magic and hash logging to syslog for example results in logs for all filetypes despite having only one alert rule for Win32 PE files. I'd like it to only log the PE files.

DH Updated by Duane Howard about 9 years ago Actions #3

Friendly ping on this?

VJ Updated by Victor Julien about 9 years ago Actions #4

  • Assignee set to Anonymous
  • Target version set to TBD

Contributions will be welcomed.

AH Updated by Andreas Herz about 7 years ago Actions #5

  • Assignee set to Community Ticket

VJ Updated by Victor Julien over 6 years ago Actions #6

  • Related to Feature #1005: conditional logging: controlling what gets logged added

VJ Updated by Victor Julien over 6 years ago Actions #7

  • Related to Feature #2055: Optionally logging on files.json - Not log every file, only certain files that are stored and extracted added

PA Updated by Philippe Antoine over 2 years ago Actions #8

Have you looked into the config keyword to be able to do this ?

Actions

Also available in: PDF Atom