Actions
Task #4772
opentracking: parity between fields logged and fields available for detection
Effort:
Difficulty:
Label:
Updated by Philippe Antoine over 2 years ago
My next thing here is to look into the schema.json for integers where there are no signature keywords, starting by the flow.nbpackets or such (as I did flow.age last)
Updated by Juliana Fajardini Reichow almost 2 years ago
Added #5234 as related as it seems that we parse and log the info, but it's not accessible to the rule language.
Updated by Victor Julien about 1 year ago
@Jason Ish has a script to dump all the eve fields. Perhaps we can use it to map it to rule keywords/buffers.
Actions