Project

General

Profile

Bug #2091

nonexistent/misspelled custom fields accepted during parsing of suricata.yaml

Added by Peter Manev over 2 years ago. Updated 8 days ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

This is Suricata version 4.0dev (rev 9ff8882)

If there is misspelled or nonexistent custom field in eve.json's section Suricata would not error out/warn on start - example:


        - http:
            custom: [accept, accept-charset, accept-encoding, accept-language,
            proxy-authenticate, referrer, refresh, retry-after, server,
            set-cookie, trailer, transfer-encoding, upgrade, vary, warning,
            www-authenticate, mychemicalromance]
        - smtp:
            custom: [received, sensitivity, organization, content-md5, date, mychemicalromance]

History

#1

Updated by Andreas Herz about 2 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
#2

Updated by Andreas Herz 11 days ago

But it doesn't hurt either right?

#3

Updated by Jason Ish 9 days ago

Andreas Herz wrote:

But it doesn't hurt either right?

Doesn't hurt, but may improve user experience. Just in case you entered "receved" by accident and can't figure out why you are not seeing that in the output.

#4

Updated by Peter Manev 8 days ago

Also it may not err on a filed we don't parse or support yet and leave the user with the wrong impression that everything is ok and expecting to see those values.

Also available in: Atom PDF