Actions
Bug #3087
openPrelude output IDMEF message issue
Affected Versions:
Effort:
low
Difficulty:
low
Label:
Description
Hello,
The Prelude Siem output (IDMEF) of Suricata might be confused from version 4.1.2. The alert.classification.text field which should contain the signature name (for example ET Policy...) swapped with alert.assessment.impact.description(classification for example Corporate policy violation). In other words after version 4.1.2 we see the classification instead of the signature name and in the description we could see the signature name where was previously the classification.
Could you please check it?
Thank you!
Files
Updated by Victor Julien about 4 years ago
- Assignee set to Community Ticket
- Target version set to TBD
Updated by Victor Julien about 4 years ago
I've pinged Thomas who has been maintaining this code recently.
Actions
#3
Updated by Andrew Goldy about 4 years ago
- File prelude.PNG prelude.PNG added
- File prelude1.PNG prelude1.PNG added
To visualize the problem:
As the the prewikka console shows the text message is swapped with description.
Actions