Project

General

Profile

Actions

Feature #2416

closed

Increase XFF coverage to files and http log

Added by Maurizio Abba over 3 years ago. Updated about 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

XFF support is restricted to alert events. It would be nice to increase its coverage to HTTP and alert.

This modification will require the transformation of the HttpXFFGetIP to accept flows instead of packets. This function will anyway only use p->flow, using the flow directly instead of the single packet will obtain the same effect and allow to get the correct IPs.

Actions #1

Updated by Maurizio Abba over 3 years ago

I'm not sure what logging would you include in this patch. Currently, XFF can be configured for eve-log and unified log. I added XFF support for files and http in eve-log. I didn't modify http.log, fast.log and metafiles.

Actions #2

Updated by Andreas Herz over 3 years ago

  • Target version set to TBD
Actions #3

Updated by Maurizio Abba about 3 years ago

  • Status changed from Assigned to Closed
Actions #4

Updated by Victor Julien about 3 years ago

  • Target version changed from TBD to 4.1rc1
Actions

Also available in: Atom PDF