Project

General

Profile

Actions

Feature #2096

closed
AT SD

eve: event_type for MODBUS

Feature #2096: eve: event_type for MODBUS

Added by Austin Taylor about 9 years ago. Updated almost 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Here is an example of the type of event I'm looking for with MODBUS, but this is for DNP3.

{"timestamp":"2015-10-22T04:46:25.989814-0400","flow_id":719070443301326,"pcap_cnt":837127,"event_type":"*dnp3*","src_ip":"192.168.2.166","src_port":2142,"dest_ip":"192.168.88.95","dest_port":20000,"proto":"TCP","dnp3":{"type":"request","control":{"dir":true,"pri":true,"fcb":false,"fcv":false,"function_code":4},"src":1,"dst":1024,"application":{"control":{"fir":true,"fin":true,"con":false,"uns":false,"sequence":1},"function_code":1,"objects":[{"group":60,"variation":2,"qualifier":6,"prefix_code":0,"range_code":6,"start":0,"stop":0,"count":0}],"complete":true}}}

Would like to have similar event_type generated but with MODBUS fields.


Related issues 2 (0 open2 closed)

Related to Suricata - Optimization #2782: Convert Modbus from C to RustRejectedActions
Related to Suricata - Feature #3957: Convert protocol to Rust: ModbusClosedSimon DugasActions

VJ Updated by Victor Julien almost 9 years ago Actions #1

  • Description updated (diff)
  • Assignee set to Anonymous
  • Priority changed from High to Normal
  • Target version changed from 70 to TBD

VJ Updated by Victor Julien almost 9 years ago Actions #2

  • Subject changed from Add event_type for MODBUS to eve: event_type for MODBUS

EL Updated by Eric Leblond almost 9 years ago Actions #3

  • Assignee changed from Anonymous to Eric Leblond

VJ Updated by Victor Julien about 6 years ago Actions #4

VJ Updated by Victor Julien about 6 years ago Actions #5

  • Assignee changed from Eric Leblond to OISF Dev

SB Updated by Shivani Bhardwaj over 5 years ago Actions #6

  • Related to Feature #3957: Convert protocol to Rust: Modbus added

SD Updated by Simon Dugas about 5 years ago Actions #7

Sample output is shown in this pull request which may implement this ticket:
- https://github.com/OISF/suricata/pull/5750

PA Updated by Philippe Antoine about 5 years ago Actions #8

  • Status changed from New to In Review

VJ Updated by Victor Julien almost 5 years ago Actions #9

  • Status changed from In Review to Closed
  • Assignee changed from OISF Dev to Simon Dugas
  • Target version changed from TBD to 7.0.0-beta1
Actions

Also available in: PDF Atom