Project

General

Profile

Feature #2282

event log aka weird.log

Added by Victor Julien over 2 years ago. Updated 10 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Suricata sets internal events on packet/engine/applayer errors. These can be matched on the rule language and are also counters.

The request here is to mimic Bro's 'weird.log' that logs such events.


Related issues

Related to Support #2309: SuriCon 2017 brainstormNew12/01/2017Victor JulienActions
Related to Support #2685: SuriCon 2018 brainstormNewVictor JulienActions
#1

Updated by Andreas Herz about 2 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
#2

Updated by Victor Julien about 2 years ago

#3

Updated by Victor Julien over 1 year ago

  • Effort set to medium
  • Difficulty set to low

This would involve creating a new eve packet logger that is invoked if a packet has events set. It can then loop the events and log out each of them.

#4

Updated by Raymond Hansen over 1 year ago

  • Priority changed from Normal to High
#5

Updated by Victor Julien over 1 year ago

#6

Updated by Victor Julien 11 months ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Jeff Lucovsky
  • Priority changed from High to Normal
  • Target version changed from TBD to 5.0beta1
#8

Updated by Victor Julien 11 months ago

The goal is not to add Bro weird log compatibility, but more a similar facility that is inspired by it. We want to log all the events Suricata sets when it finds anomalies in traffic.

#9

Updated by Victor Julien 10 months ago

  • Target version changed from 5.0beta1 to 5.0rc1
#10

Updated by Victor Julien 10 months ago

  • Status changed from Assigned to Closed
  • Target version changed from 5.0rc1 to 5.0beta1
  • Effort deleted (medium)
  • Difficulty deleted (low)

Also available in: Atom PDF