Actions
Bug #2206
closedeve log integration or socket output for file extraction details
Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:
Description
To ease integration for file analysis attached to suricata it would be great to include the content of the .meta files from extracted files in either eve.json or allow an additional unix socket instead of a logfile for "file-log" in the config.
Updated by Victor Julien about 7 years ago
I'm not sure I understand. The fileinfo records provide this info in eve, right?
Updated by Robert Haist about 7 years ago
Victor Julien wrote:
I'm not sure I understand. The fileinfo records provide this info in eve, right?
We investigated this further. You are right. Please excuse the spam. Issue can be closed.
Updated by Peter Manev about 7 years ago
- Status changed from New to Closed
Closing as updated/requested
Actions