Project

General

Profile

Actions

Feature #1950

open

allow configuration of file-store types

Added by Duane Howard about 8 years ago. Updated about 1 year ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

files-json.log seems to get pretty big pretty quickly. It would be nice to be able to configure which types of files it will log. Alternately being able to only log the metadata for stuff with a filestore rule could be useful.


Related issues 2 (2 open0 closed)

Related to Suricata - Feature #1005: conditional logging: controlling what gets loggedAssignedVictor JulienActions
Related to Suricata - Feature #2055: Optionally logging on files.json - Not log every file, only certain files that are stored and extractedNewOISF DevActions
Actions #1

Updated by Victor Julien almost 8 years ago

I could imagine 2 types of solutions here:

  1. add some kind of output filtering to the logger (e.g. pattern/regex match)
  2. allow rules to control such logging.

Personally I would prefer the latter although it's a more invasive change.

Actions #2

Updated by chris K. almost 8 years ago

I noticed this issue with the eve-log also. Enabling file magic and hash logging to syslog for example results in logs for all filetypes despite having only one alert rule for Win32 PE files. I'd like it to only log the PE files.

Actions #3

Updated by Duane Howard over 7 years ago

Friendly ping on this?

Actions #4

Updated by Victor Julien over 7 years ago

  • Assignee set to Anonymous
  • Target version set to TBD

Contributions will be welcomed.

Actions #5

Updated by Andreas Herz almost 6 years ago

  • Assignee set to Community Ticket
Actions #6

Updated by Victor Julien about 5 years ago

  • Related to Feature #1005: conditional logging: controlling what gets logged added
Actions #7

Updated by Victor Julien about 5 years ago

  • Related to Feature #2055: Optionally logging on files.json - Not log every file, only certain files that are stored and extracted added
Actions #8

Updated by Philippe Antoine about 1 year ago

Have you looked into the config keyword to be able to do this ?

Actions

Also available in: Atom PDF