Project

General

Profile

Actions

Feature #6210

open

outputs: add verdict event type

Added by Juliana Fajardini Reichow 10 months ago. Updated 8 months ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

We're soon to have a verdict logged out with alerts and drops, but we think there is
value in adding that as an independent field, too, to log more situations that affect packets.


Related issues 2 (1 open1 closed)

Related to Suricata - Bug #5464: eve: if alert and drop rules match for a packet, "alert.action" is ambigiousClosedJuliana Fajardini ReichowActions
Related to Suricata - Feature #6215: Exception policy log outputAssignedJuliana Fajardini ReichowActions
Actions

Also available in: Atom PDF