Project

General

Profile

Actions

Feature #2282

closed

event log aka weird.log

Added by Victor Julien almost 4 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Suricata sets internal events on packet/engine/applayer errors. These can be matched on the rule language and are also counters.

The request here is to mimic Bro's 'weird.log' that logs such events.


Related issues

Related to Task #2309: SuriCon 2017 brainstormNewVictor JulienActions
Related to Task #2685: SuriCon 2018 brainstormNewVictor JulienActions
Actions #1

Updated by Andreas Herz almost 4 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
Actions #2

Updated by Victor Julien almost 4 years ago

  • Related to Task #2309: SuriCon 2017 brainstorm added
Actions #3

Updated by Victor Julien about 3 years ago

  • Effort set to medium
  • Difficulty set to low

This would involve creating a new eve packet logger that is invoked if a packet has events set. It can then loop the events and log out each of them.

Actions #4

Updated by Raymond Hansen almost 3 years ago

  • Priority changed from Normal to High
Actions #5

Updated by Victor Julien almost 3 years ago

  • Related to Task #2685: SuriCon 2018 brainstorm added
Actions #6

Updated by Victor Julien over 2 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Jeff Lucovsky
  • Priority changed from High to Normal
  • Target version changed from TBD to 5.0beta1
Actions #8

Updated by Victor Julien over 2 years ago

The goal is not to add Bro weird log compatibility, but more a similar facility that is inspired by it. We want to log all the events Suricata sets when it finds anomalies in traffic.

Actions #9

Updated by Victor Julien over 2 years ago

  • Target version changed from 5.0beta1 to 5.0rc1
Actions #10

Updated by Victor Julien over 2 years ago

  • Status changed from Assigned to Closed
  • Target version changed from 5.0rc1 to 5.0beta1
  • Effort deleted (medium)
  • Difficulty deleted (low)
Actions

Also available in: Atom PDF