Project

General

Profile

Actions

Feature #2196

closed

Add flow_id to the file extracted .meta file

Added by Mikael Keri about 7 years ago. Updated about 4 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

To enable easier mappings of extracted files and connected alerts I suggest adding the field "flow_id" to the corresponding .meta file.

If you would like or need more information why I like this feature or need someone to to test it I would gladly help out


Related issues 2 (1 open1 closed)

Related to Suricata - Feature #2145: Relate directly flowid with certificate fileNewOISF Dev06/14/2017Actions
Related to Suricata - Task #2959: deprecate: filestore v1ClosedJason IshActions
Actions #1

Updated by Andreas Herz about 7 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
Actions #2

Updated by Victor Julien about 5 years ago

  • Related to Feature #2145: Relate directly flowid with certificate file added
Actions #3

Updated by Victor Julien over 4 years ago

This is only relevant to filestore v1, which will be removed soon.

Actions #4

Updated by Victor Julien over 4 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Jason Ish

For v2 we support it, but a SV test is missing.

Actions #5

Updated by Jason Ish over 4 years ago

  • Target version changed from TBD to 6.0.0beta1
Actions #6

Updated by Jason Ish over 4 years ago

  • Related to Task #2959: deprecate: filestore v1 added
Actions #7

Updated by Jason Ish over 4 years ago

Add SV test to verify file-store v2 has a flow_id in the fileinfo records.

Actions

Also available in: Atom PDF