Project

General

Profile

Actions

Feature #4974

open

Log references to Eve

Added by Jason Ish over 2 years ago. Updated 15 days ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Its been discussed a few time of references should be logged to eve. This would give alerts more context without access to the rule. However, logging the rule is also an option.

The reference logged should probably be the fully expanded reference.

Actions #1

Updated by Philippe Antoine over 2 years ago

See https://github.com/OISF/suricata/pull/6677 : Remove unused (for now) references from signature

Actions #2

Updated by Jeff Lucovsky about 1 month ago

  • Status changed from New to In Review
  • Assignee changed from OISF Dev to Jeff Lucovsky
Actions #3

Updated by Juliana Fajardini Reichow 15 days ago

  • Target version changed from TBD to 8.0.0-beta1
Actions

Also available in: Atom PDF