Project

General

Custom queries

Profile

Actions

Task #4772

open

tracking: parity between fields logged and fields available for detection

Added by Victor Julien over 3 years ago. Updated 2 months ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Subtasks 7 (4 open3 closed)

Feature #4153: app-layer: rust derive style macros to generate common codeAssignedJason IshActions
Optimization #4154: Rust Parsers: Abstract AppLayer events to a derive macroClosedJason IshActions
Feature #5642: DNS: parity between log fields and detectionAssignedJason IshActions
Feature #6621: dns: add keyword for dns rcode: dns.rcodeClosedHadiqa Alamdar BukhariActions
Feature #6666: dns: add keyword for dns rrtype: dns.rrtypeClosedHadiqa Alamdar BukhariActions
Task #6476: ftp: parity of logging and detection buffersIn ProgressJeff LucovskyActions
Story #6597: rules: improve rules keyword/output parityNewVictor JulienActions

Related issues 9 (7 open2 closed)

Related to Suricata - Task #4762: Suricon 2021 brainstormAssignedVictor JulienActions
Related to Suricata - Feature #4174: tracking: app-layer frame inspection supportIn ProgressVictor JulienActions
Related to Suricata - Feature #6164: rules: allow matching on flow pkts and bytesClosedPhilippe AntoineActions
Related to Suricata - Feature #5234: tls: subjectAltName bufferClosedShivani BhardwajActions
Related to Suricata - Task #6443: Suricon 2023 brainstormAssignedVictor JulienActions
Related to Suricata - Task #6473: detect: smtp keyword coverageAssignedVictor JulienActions
Related to Suricata - Feature #4876: Additional FTP BuffersNewJeff LucovskyActions
Related to Suricata - Task #6463: eve/output: investigate how to track coverage / parityIn ProgressJason IshActions
Related to Suricata - Feature #7100: smb: additional keywordsNewOISF DevActions
Actions #6

Updated by Philippe Antoine over 2 years ago

My next thing here is to look into the schema.json for integers where there are no signature keywords, starting by the flow.nbpackets or such (as I did flow.age last)

Actions #9

Updated by Juliana Fajardini Reichow almost 2 years ago

Added #5234 as related as it seems that we parse and log the info, but it's not accessible to the rule language.

Actions #18

Updated by Victor Julien about 1 year ago

@Jason Ish has a script to dump all the eve fields. Perhaps we can use it to map it to rule keywords/buffers.

Actions

Also available in: Atom PDF