Project

General

Profile

Actions

Bug #5464

closed

eve: if alert and drop rules match for a packet, "alert.action" is ambigious

Added by Victor Julien almost 2 years ago. Updated 10 months ago.

Status:
Closed
Priority:
High
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The alert record produced for the alert rule will say "allowed". The alert record produced for the drop rule will say "blocked". There is no indication which of these "won" in the alert record itself.

I think the "allowed" for alert is a bit misleading. Alert is passive so it sets no action. So this could perhaps be changed into something more appropriate, like "action: alert".

Additionally it might be a good idea to list the action that was applied to the packet in the record separately, as the authoritative field to indicate what the decision of suricata on this packet was.


Related issues 3 (2 open1 closed)

Related to Suricata - Task #6084: output/alert: enable logging `PASS` alertsAssignedJuliana Fajardini ReichowActions
Related to Suricata - Feature #6210: outputs: add verdict event typeNewJuliana Fajardini ReichowActions
Related to Suricata - Bug #5794: eve: if alert and drop rules match for a packet, "alert.action" is ambigious (6.0.x backport)ClosedJuliana Fajardini ReichowActions
Actions

Also available in: Atom PDF