Project

General

Profile

Actions

Feature #4573

open

add IPS drop total to eve log output

Added by Corey Thomas over 1 year ago. Updated 7 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

It would be useful to have the stats metric for total IPS drops in eve output. Probably similar to the alert count as part of suricata engine output. The field name should be clear that it's ips or alert drops.

e.g.

{"timestamp":"2021-08-03T13:15:28.965147+0000","log_level":"Info","event_type":"engine","engine":{"message":"Alerts: 56893"}}
{"timestamp":"2021-08-03T13:15:28.965147+0000","log_level":"Info","event_type":"engine","engine":{"message":"IPS_Drops: 100"}}


Related issues 1 (1 open0 closed)

Related to Feature #4756: capture: support ips stats for all IPS capture methodsIn ProgressJeff LucovskyActions
Actions #1

Updated by Victor Julien about 1 year ago

  • Related to Feature #4756: capture: support ips stats for all IPS capture methods added
Actions #2

Updated by Jeff Lucovsky 7 months ago

  • Target version set to TBD
Actions

Also available in: Atom PDF