Project

General

Profile

Actions

Bug #4439

open

Log data way in alert

Added by Eric Leblond 5 months ago. Updated 5 months ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
-
Affected Versions:
Effort:
Difficulty:
Label:

Description

If the alert event contains the flow information it is not possible to know which from the source or the destination IP is the client for the flow.

Actions #1

Updated by Eric Leblond 5 months ago

  • Status changed from New to In Review
Actions #2

Updated by Odin Jenseg 5 months ago

Hi Eric,

I think this also would make sense to include this type of information for the event_type=fileinfo, since a fileinfo event can be triggered in both direction.

Actions

Also available in: Atom PDF