Project

General

Profile

Actions

Feature #3296

open
AH CT

Include in the fileinfo if it was a duplicate

Feature #3296: Include in the fileinfo if it was a duplicate

Added by Andreas Herz over 6 years ago. Updated over 5 years ago.

Status:
Feedback
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

In filestore v2 files are stored by their sha256. When it finds a duplicate, it will only update the timestamp.

I think the request here is to log in some way the number of times this file was already seen.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #3288: Suricon 2019 brainstormAssignedVictor JulienActions

VJ Updated by Victor Julien over 6 years ago Actions #1

  • Parent task deleted (#3288)

VJ Updated by Victor Julien over 6 years ago Actions #2

  • Related to Task #3288: Suricon 2019 brainstorm added

VJ Updated by Victor Julien over 6 years ago Actions #3

  • Description updated (diff)
  • Status changed from New to Feedback
  • Assignee changed from Community Ticket to Stian Bergseth

Stian, IIRC you brought this up. Could you describe what you are after a bit more?

SB Updated by Stian Bergseth over 6 years ago Actions #4

I did not bring it up actually :)

But iirc the wanted feature was to update the metainfo in filestore with first seen, last seen and how many times seen. I guess that should not be too complicated?

VJ Updated by Victor Julien over 6 years ago Actions #5

  • Assignee changed from Stian Bergseth to Community Ticket

Hah, sorry! Doesn't sound over complicated, although I'm not sure what would happen if multiple threads would try to rewrite this file at the same time.

JI Updated by Jason Ish over 6 years ago Actions #6

From my notes it was to simply create a flag in the fileinfo entry that it was a dup. I think its simple enough. Of course, we'd only catch this case if the file was seen multiple times within your retention window.

VJ Updated by Victor Julien over 5 years ago Actions #7

It seems this is something that could be inferred from the fileinfo eve logs

Actions

Also available in: PDF Atom