Increase XFF coverage to files and http log
XFF support is restricted to alert events. It would be nice to increase its coverage to HTTP and alert.
This modification will require the transformation of the HttpXFFGetIP to accept flows instead of packets. This function will anyway only use p->flow, using the flow directly instead of the single packet will obtain the same effect and allow to get the correct IPs.
Updated by Maurizio Abba about 5 years ago
I'm not sure what logging would you include in this patch. Currently, XFF can be configured for eve-log and unified log. I added XFF support for files and http in eve-log. I didn't modify http.log, fast.log and metafiles.
Updated by Andreas Herz about 5 years ago
- Target version set to TBD
Updated by Maurizio Abba over 4 years ago
- Status changed from Assigned to Closed
Updated by Victor Julien over 4 years ago
- Target version changed from TBD to 4.1rc1