Project

General

Profile

Actions

Bug #5464

closed

eve: if alert and drop rules match for a packet, "alert.action" is ambigious

Added by Victor Julien over 2 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
High
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The alert record produced for the alert rule will say "allowed". The alert record produced for the drop rule will say "blocked". There is no indication which of these "won" in the alert record itself.

I think the "allowed" for alert is a bit misleading. Alert is passive so it sets no action. So this could perhaps be changed into something more appropriate, like "action: alert".

Additionally it might be a good idea to list the action that was applied to the packet in the record separately, as the authoritative field to indicate what the decision of suricata on this packet was.


Related issues 3 (1 open2 closed)

Related to Suricata - Task #6084: output/alert: enable logging `PASS` alertsClosedActions
Related to Suricata - Feature #6210: outputs: add verdict event typeNewJuliana Fajardini ReichowActions
Related to Suricata - Bug #5794: eve: if alert and drop rules match for a packet, "alert.action" is ambigious (6.0.x backport)ClosedJuliana Fajardini ReichowActions
Actions

Also available in: Atom PDF