Project

General

Profile

Feature #385

Configuration option to log all known (pcap) data for a stream when an alert fires

Added by David Wharton over 8 years ago. Updated 7 months ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

This is a request to be able to configure Suricata to log as much of a stream that it can leading up to an alert. For example, if an alert is generated, this configuration directive would tell Suricata to log as much of the stream that it knows about (e.g. what is in memory) up until and including the data that caused the alert, to disk. Data after an alert can be set by tagging directives but I think it would be handy to be able to configure Suricata to log all traffic it has in memory for a stream that generates an alert. Logging of network data would of course be in libpcap format (see also Feature #384 -- https://redmine.openinfosecfoundation.org/issues/384).


Related issues

Related to Task #2309: SuriCon 2017 brainstormNewVictor JulienActions
Related to Documentation #2219: Save pcap only if alertAssignedJason IshActions
Related to Task #2685: SuriCon 2018 brainstormNewVictor JulienActions
Is duplicate of Feature #120: Capture full session on alertNewCommunity TicketActions
#1

Updated by Victor Julien about 8 years ago

  • Assignee set to OISF Dev
  • Priority changed from Low to Normal
  • Target version set to TBD

In case of an alert generated based on the application layer state (e.g. HTTP), this is already what we do in Unified2. For raw stream alerts we can probably try to do that as well.

#2

Updated by Victor Julien over 2 years ago

  • Related to Task #2309: SuriCon 2017 brainstorm added
#3

Updated by Victor Julien almost 2 years ago

  • Related to Feature #120: Capture full session on alert added
#4

Updated by Victor Julien almost 2 years ago

#5

Updated by Raymond Hansen over 1 year ago

  • Assignee changed from OISF Dev to Maurizio Abba
#6

Updated by Victor Julien over 1 year ago

  • Related to Task #2685: SuriCon 2018 brainstorm added
#7

Updated by Victor Julien about 1 year ago

Hi Maurizio, are you still planning to submit a PR for this?

#8

Updated by Victor Julien 8 months ago

  • Assignee changed from Maurizio Abba to Community Ticket
#9

Updated by Andreas Herz 7 months ago

  • Status changed from New to Closed

Issue #120 is the same but less specific

#10

Updated by Victor Julien 7 months ago

  • Related to deleted (Feature #120: Capture full session on alert)
#11

Updated by Victor Julien 7 months ago

  • Is duplicate of Feature #120: Capture full session on alert added

Also available in: Atom PDF