Project

General

Profile

Actions

Feature #2282

closed

event log aka weird.log

Added by Victor Julien about 7 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Suricata sets internal events on packet/engine/applayer errors. These can be matched on the rule language and are also counters.

The request here is to mimic Bro's 'weird.log' that logs such events.


Related issues 2 (2 open0 closed)

Related to Suricata - Task #2309: SuriCon 2017 brainstormAssignedVictor JulienActions
Related to Suricata - Task #2685: SuriCon 2018 brainstormAssignedVictor JulienActions
Actions #1

Updated by Andreas Herz almost 7 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
Actions #2

Updated by Victor Julien almost 7 years ago

  • Related to Task #2309: SuriCon 2017 brainstorm added
Actions #3

Updated by Victor Julien about 6 years ago

  • Effort set to medium
  • Difficulty set to low

This would involve creating a new eve packet logger that is invoked if a packet has events set. It can then loop the events and log out each of them.

Actions #4

Updated by Raymond Hansen about 6 years ago

  • Priority changed from Normal to High
Actions #5

Updated by Victor Julien about 6 years ago

  • Related to Task #2685: SuriCon 2018 brainstorm added
Actions #6

Updated by Victor Julien over 5 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Jeff Lucovsky
  • Priority changed from High to Normal
  • Target version changed from TBD to 5.0beta1
Actions #8

Updated by Victor Julien over 5 years ago

The goal is not to add Bro weird log compatibility, but more a similar facility that is inspired by it. We want to log all the events Suricata sets when it finds anomalies in traffic.

Actions #9

Updated by Victor Julien over 5 years ago

  • Target version changed from 5.0beta1 to 5.0rc1
Actions #10

Updated by Victor Julien over 5 years ago

  • Status changed from Assigned to Closed
  • Target version changed from 5.0rc1 to 5.0beta1
  • Effort deleted (medium)
  • Difficulty deleted (low)
Actions

Also available in: Atom PDF