Allow log for payload and packet only for defined sid
Suricata config file having a feature for logging for all payload and packet, but does not have a feature for only defined sids.
- payload: yes # enable dumping payload in Base64
- payload-buffer-size: 4kb # max size of payload buffer to output in eve-log
- payload-printable: yes # enable dumping payload in printable (lossy) format
- packet: yes # enable dumping of packet (without stream segments)
Can we have a feature logging payload and packet only defined sids?
Updated by Andreas Herz almost 5 years ago
- Assignee changed from Victor Julien to OISF Dev
- Target version set to TBD
So you want to have a list of sids that should be relevant for that logging and skip all the others for that part of the logging? I would implement it either as some keyword or as a dedicated file like threshold.config. Postprocessing is no solution for you to filter them?
Updated by Andreas Herz over 3 years ago
- Status changed from New to Closed
Hi, we're closing this issue since there have been no further responses.
If you think this bug is still relevant, try to test it again with the
most recent version of suricata and reopen the issue. If you want to
improve the bug report please take a look at