Actions
Bug #4860
closed
PA
PA
eve.json remove app-layer specific fields from root object
Bug #4860:
eve.json remove app-layer specific fields from root object
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport, Needs backport to 5.0, Needs backport to 6.0
Description
Running jq 'select(.command)' tests/*/output/eve.json in Suricata-verify gives output containing
{
"timestamp": "2013-06-17T21:59:47.428041+0000",
"event_type": "alert",
"filename": "temp.txt",
"command": "RETR",
"app_proto": "ftp-data",
}
where both filename and command should belong to a ftp-data object
PA Updated by Philippe Antoine over 4 years ago
- Related to Feature #1369: eve: json schema added
PA Updated by Philippe Antoine over 4 years ago
- Subject changed from eve.json ftp-data in root object to eve.json remove app-layer specific fiels from root object
PA Updated by Philippe Antoine over 4 years ago
This is also true for xff which belongs to HTTP1
PA Updated by Philippe Antoine over 4 years ago
- Status changed from New to In Review
JL Updated by Jeff Lucovsky over 4 years ago
- Subject changed from eve.json remove app-layer specific fiels from root object to eve.json remove app-layer specific fields from root object
JL Updated by Jeff Lucovsky over 4 years ago
- Copied to Bug #4884: eve.json remove app-layer specific fields from root object added
JL Updated by Jeff Lucovsky over 4 years ago
- Copied to Bug #4885: eve.json remove app-layer specific fields from root object added
PA Updated by Philippe Antoine about 4 years ago
- Status changed from In Review to Closed
Actions