Project

General

Profile

Feature #2282

event log aka weird.log

Added by Victor Julien over 2 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Suricata sets internal events on packet/engine/applayer errors. These can be matched on the rule language and are also counters.

The request here is to mimic Bro's 'weird.log' that logs such events.


Related issues

Related to Task #2309: SuriCon 2017 brainstormNewVictor JulienActions
Related to Task #2685: SuriCon 2018 brainstormNewVictor JulienActions
#1

Updated by Andreas Herz over 2 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
#2

Updated by Victor Julien over 2 years ago

  • Related to Task #2309: SuriCon 2017 brainstorm added
#3

Updated by Victor Julien over 1 year ago

  • Effort set to medium
  • Difficulty set to low

This would involve creating a new eve packet logger that is invoked if a packet has events set. It can then loop the events and log out each of them.

#4

Updated by Raymond Hansen over 1 year ago

  • Priority changed from Normal to High
#5

Updated by Victor Julien over 1 year ago

  • Related to Task #2685: SuriCon 2018 brainstorm added
#6

Updated by Victor Julien about 1 year ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Jeff Lucovsky
  • Priority changed from High to Normal
  • Target version changed from TBD to 5.0beta1
#8

Updated by Victor Julien about 1 year ago

The goal is not to add Bro weird log compatibility, but more a similar facility that is inspired by it. We want to log all the events Suricata sets when it finds anomalies in traffic.

#9

Updated by Victor Julien about 1 year ago

  • Target version changed from 5.0beta1 to 5.0rc1
#10

Updated by Victor Julien about 1 year ago

  • Status changed from Assigned to Closed
  • Target version changed from 5.0rc1 to 5.0beta1
  • Effort deleted (medium)
  • Difficulty deleted (low)

Also available in: Atom PDF