Project

General

Profile

Actions

Bug #5769

closed

Incomplete values for .stats."app_layer".flow.proto

Added by Philippe Antoine 9 months ago. Updated 9 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

With ftp or whatever protocol
The two commands do not give the same result

jq 'select(.event_type=="flow" and .app_proto=="ftp") | .app_proto'  log/eve.json | wc -l
jq 'select(.event_type=="stats") | .stats."app_layer".flow.ftp' log/eve.json 

Related issues 1 (1 open0 closed)

Blocks Suricata - Feature #1125: smtp: improve protocol detectionIn ReviewPhilippe AntoineActions
Actions #1

Updated by Philippe Antoine 9 months ago

  • Status changed from New to In Review
  • Target version changed from TBD to 7.0.0-rc1
Actions #2

Updated by Philippe Antoine 9 months ago

Actions #3

Updated by Philippe Antoine 9 months ago

  • Status changed from In Review to Closed
Actions

Also available in: Atom PDF