Project

General

Profile

Actions

Documentation #5494

closed
JF JF

userguide: update tls eve-log fields 'not_before' and 'not_after'

Documentation #5494: userguide: update tls eve-log fields 'not_before' and 'not_after'

Added by Juliana Fajardini Reichow over 3 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

It was reported that our documentation mentioned the tls fields 'not_before' and 'not_after'
as possible custom fields for the tls events in our eve-log, whereas in fact the fields
themselves are written as 'notbefore' and 'notafter', which led to confusion for folks trying
to follow the documentation to parse our logs.

Our documentation: https://suricata.readthedocs.io/en/latest/output/eve/eve-json-format.html#id10
Example check for our eve-log: https://github.com/OISF/suricata-verify/blob/master/tests/bug-2646-01/test.yaml#L20

Update our documentation to reflect what is seen in our logs.


Subtasks 3 (0 open3 closed)

Documentation #6505: userguide: update tls eve-log fields 'not_before' and 'not_after' (6.0.x backport)ClosedActions
Documentation #6512: userguide: update tls eve-log fields 'not_before' and 'not_after' (6.0.x backport)ClosedJuliana Fajardini ReichowActions
Documentation #6513: userguide: update tls eve-log fields 'not_before' and 'not_after' (7.0.x backport)ClosedJuliana Fajardini ReichowActions

Related issues 1 (0 open1 closed)

Related to Suricata - Documentation #6288: eve/schema: generate tables of data for app-layer protocolsClosedJason IshActions

JF Updated by Juliana Fajardini Reichow over 3 years ago Actions #1

  • Subject changed from userguide: update tls eve-log field 'not_before' and 'not_after' to userguide: update tls eve-log fields 'not_before' and 'not_after'
  • Description updated (diff)

JF Updated by Juliana Fajardini Reichow over 3 years ago Actions #2

  • Affected Versions git main added

JF Updated by Juliana Fajardini Reichow over 3 years ago Actions #3

  • Target version changed from TBD to 7.0.0-rc2

JF Updated by Juliana Fajardini Reichow about 3 years ago Actions #5

Something like that, or if we could add documentation to the schema itself? Would that work?

JF Updated by Juliana Fajardini Reichow about 3 years ago Actions #6

  • Label Needs backport added

VJ Updated by Victor Julien about 3 years ago Actions #7

  • Target version changed from 7.0.0-rc2 to 8.0.0-beta1

JF Updated by Juliana Fajardini Reichow over 2 years ago Actions #8

  • Label Needs backport to 6.0, Needs backport to 7.0 added

JF Updated by Juliana Fajardini Reichow over 2 years ago Actions #9

  • Status changed from New to In Progress

JF Updated by Juliana Fajardini Reichow over 2 years ago Actions #10

  • Related to Documentation #6288: eve/schema: generate tables of data for app-layer protocols added

JF Updated by Juliana Fajardini Reichow over 2 years ago Actions #11

  • Status changed from In Progress to In Review

OT Updated by OISF Ticketbot over 2 years ago Actions #12

  • Subtask #6505 added

OT Updated by OISF Ticketbot over 2 years ago Actions #13

  • Label deleted (Needs backport, Needs backport to 6.0, Needs backport to 7.0)

SB Updated by Shivani Bhardwaj over 2 years ago Actions #14

  • Label Needs backport to 6.0, Needs backport to 7.0 added

OT Updated by OISF Ticketbot over 2 years ago Actions #15

  • Subtask #6512 added

OT Updated by OISF Ticketbot over 2 years ago Actions #16

  • Subtask #6513 added

OT Updated by OISF Ticketbot over 2 years ago Actions #17

  • Label deleted (Needs backport to 6.0)

OT Updated by OISF Ticketbot over 2 years ago Actions #18

  • Label deleted (Needs backport to 7.0)

JF Updated by Juliana Fajardini Reichow over 2 years ago Actions #19

  • Status changed from In Review to Resolved

JF Updated by Juliana Fajardini Reichow over 2 years ago Actions #20

  • Status changed from Resolved to Closed
Actions

Also available in: PDF Atom