Project

General

Custom queries

Profile

Actions

Bug #5464

closed

eve: if alert and drop rules match for a packet, "alert.action" is ambigious

Added by Victor Julien almost 3 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
High
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The alert record produced for the alert rule will say "allowed". The alert record produced for the drop rule will say "blocked". There is no indication which of these "won" in the alert record itself.

I think the "allowed" for alert is a bit misleading. Alert is passive so it sets no action. So this could perhaps be changed into something more appropriate, like "action: alert".

Additionally it might be a good idea to list the action that was applied to the packet in the record separately, as the authoritative field to indicate what the decision of suricata on this packet was.


Related issues 3 (1 open2 closed)

Related to Suricata - Task #6084: output/alert: enable logging `PASS` alertsClosedActions
Related to Suricata - Feature #6210: outputs: add verdict event typeNewJuliana Fajardini ReichowActions
Related to Suricata - Bug #5794: eve: if alert and drop rules match for a packet, "alert.action" is ambigious (6.0.x backport)ClosedJuliana Fajardini ReichowActions
#1

Updated by Victor Julien over 2 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Juliana Fajardini Reichow
  • Target version changed from TBD to 7.0.0-rc1
  • Label Needs backport to 6.0 added
#4

Updated by Juliana Fajardini Reichow over 2 years ago

  • Status changed from Assigned to In Review
#5

Updated by Shivani Bhardwaj over 2 years ago

  • Subtask #5794 added
#6

Updated by Shivani Bhardwaj over 2 years ago

  • Label deleted (Needs backport to 6.0)
#10

Updated by Victor Julien over 2 years ago

  • Target version changed from 7.0.0-rc1 to 7.0.0-rc2
#12

Updated by Victor Julien about 2 years ago

  • Target version changed from 7.0.0-rc2 to 7.0.0
#13

Updated by Juliana Fajardini Reichow about 2 years ago

  • Status changed from In Review to In Progress
#15

Updated by Juliana Fajardini Reichow almost 2 years ago

  • Status changed from In Progress to In Review
#16

Updated by Victor Julien almost 2 years ago

  • Related to Task #6084: output/alert: enable logging `PASS` alerts added
#17

Updated by Juliana Fajardini Reichow almost 2 years ago

  • Related to Feature #6210: outputs: add verdict event type added
#18

Updated by Victor Julien almost 2 years ago

  • Status changed from In Review to Resolved
#19

Updated by Victor Julien almost 2 years ago

  • Subtask deleted (#5794)
#20

Updated by Victor Julien almost 2 years ago

  • Related to Bug #5794: eve: if alert and drop rules match for a packet, "alert.action" is ambigious (6.0.x backport) added
#21

Updated by Victor Julien almost 2 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF