Project

General

Profile

Actions

Feature #2020

closed
EC

eve: add body of signature to eve.json alert

Feature #2020: eve: add body of signature to eve.json alert

Added by erik clark about 9 years ago. Updated about 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
Effort:
Difficulty:
Label:

Description

This is a request to add the body of a signature to the eve.json alert when it is fired. When an analyst examines an alert, having the payload is excellent, but without the context of the raw rule (which is of varying use depending on the analysts skill), sometimes work is put in on what would clearly be a false positive with the context of the rule in the alert.

This was submitted after discussion with Jason Ish.

VJ Updated by Victor Julien about 9 years ago Actions #1

  • Subject changed from Add body of signature to eve.json alert to eve: add body of signature to eve.json alert
  • Target version set to TBD

AH Updated by Andreas Herz almost 9 years ago Actions #2

  • Assignee set to Anonymous

MN Updated by Martin Natano over 8 years ago Actions #3

MN Updated by Martin Natano over 8 years ago Actions #4

Update PR available here: https://github.com/inliniac/suricata/pull/2881 ('signature-text' replaced with 'rule', as suggested by jasonish)

MN Updated by Martin Natano over 8 years ago Actions #5

Update PR available here: https://github.com/inliniac/suricata/pull/2897 (proper error checking in out of memory conditions; noticed by inliniac)

JI Updated by Jason Ish about 8 years ago Actions #6

  • Status changed from New to Closed
  • Target version changed from TBD to 4.1beta1
Actions

Also available in: PDF Atom