Project

General

Profile

Actions

Documentation #5494

closed

userguide: update tls eve-log fields 'not_before' and 'not_after'

Added by Juliana Fajardini Reichow over 2 years ago. Updated 11 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

It was reported that our documentation mentioned the tls fields 'not_before' and 'not_after'
as possible custom fields for the tls events in our eve-log, whereas in fact the fields
themselves are written as 'notbefore' and 'notafter', which led to confusion for folks trying
to follow the documentation to parse our logs.

Our documentation: https://suricata.readthedocs.io/en/latest/output/eve/eve-json-format.html#id10
Example check for our eve-log: https://github.com/OISF/suricata-verify/blob/master/tests/bug-2646-01/test.yaml#L20

Update our documentation to reflect what is seen in our logs.


Subtasks 3 (0 open3 closed)

Documentation #6505: userguide: update tls eve-log fields 'not_before' and 'not_after' (6.0.x backport)ClosedActions
Documentation #6512: userguide: update tls eve-log fields 'not_before' and 'not_after' (6.0.x backport)ClosedJuliana Fajardini ReichowActions
Documentation #6513: userguide: update tls eve-log fields 'not_before' and 'not_after' (7.0.x backport)ClosedJuliana Fajardini ReichowActions

Related issues 1 (1 open0 closed)

Related to Suricata - Documentation #6288: eve/schema: generate tables of data for app-layer protocolsIn ProgressJason IshActions
Actions #1

Updated by Juliana Fajardini Reichow over 2 years ago

  • Subject changed from userguide: update tls eve-log field 'not_before' and 'not_after' to userguide: update tls eve-log fields 'not_before' and 'not_after'
  • Description updated (diff)
Actions #2

Updated by Juliana Fajardini Reichow over 2 years ago

  • Affected Versions git master added
Actions #3

Updated by Juliana Fajardini Reichow almost 2 years ago

  • Target version changed from TBD to 7.0.0-rc2
Actions #5

Updated by Juliana Fajardini Reichow almost 2 years ago

Something like that, or if we could add documentation to the schema itself? Would that work?

Actions #6

Updated by Juliana Fajardini Reichow almost 2 years ago

  • Label Needs backport added
Actions #7

Updated by Victor Julien almost 2 years ago

  • Target version changed from 7.0.0-rc2 to 8.0.0-beta1
Actions #8

Updated by Juliana Fajardini Reichow about 1 year ago

  • Label Needs backport to 6.0, Needs backport to 7.0 added
Actions #9

Updated by Juliana Fajardini Reichow about 1 year ago

  • Status changed from New to In Progress
Actions #10

Updated by Juliana Fajardini Reichow about 1 year ago

  • Related to Documentation #6288: eve/schema: generate tables of data for app-layer protocols added
Actions #11

Updated by Juliana Fajardini Reichow about 1 year ago

  • Status changed from In Progress to In Review
Actions #12

Updated by OISF Ticketbot about 1 year ago

  • Subtask #6505 added
Actions #13

Updated by OISF Ticketbot about 1 year ago

  • Label deleted (Needs backport, Needs backport to 6.0, Needs backport to 7.0)
Actions #14

Updated by Shivani Bhardwaj about 1 year ago

  • Label Needs backport to 6.0, Needs backport to 7.0 added
Actions #15

Updated by OISF Ticketbot about 1 year ago

  • Subtask #6512 added
Actions #16

Updated by OISF Ticketbot about 1 year ago

  • Subtask #6513 added
Actions #17

Updated by OISF Ticketbot about 1 year ago

  • Label deleted (Needs backport to 6.0)
Actions #18

Updated by OISF Ticketbot about 1 year ago

  • Label deleted (Needs backport to 7.0)
Actions #19

Updated by Juliana Fajardini Reichow about 1 year ago

  • Status changed from In Review to Resolved
Actions #20

Updated by Juliana Fajardini Reichow 11 months ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF