Project

General

Profile

Actions

Feature #6079

open

eve/dcerpc: eve/smb: log dcerpc uuid with request/response txs

Added by Victor Julien 11 months ago. Updated 20 days ago.

Status:
Assigned
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Need the UUID with the opnum.

Actions #1

Updated by Juliana Fajardini Reichow 11 months ago

  • Target version changed from 7.0.0-rc2 to 8.0.0-beta1
Actions #2

Updated by Shivani Bhardwaj 20 days ago

It seems to me that this feature is already in place. If an SMB request is DCERPC and has interfaces, they are logged along with the opnum.
Code where this happens: https://github.com/OISF/suricata/blob/master/rust/src/smb/log.rs#L334
Also verified in the existing s-v test smb-dce_opnum.

@Peter Manev I remember you coming up with this issue. Could you please verify this is up to your expectations or if I am misunderstanding what's needed?

Actions

Also available in: Atom PDF