Project

General

Profile

Actions

Bug #6458

open

eve/http: discrepancy in http events and http objects logged in alerts

Added by Jason Ish 6 months ago. Updated 6 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

For example, the HTTP object in an HTTP record might be different than the HTTP object in an alert object.

The same has been seen in DNS and is likely to be seen in other protocols.


Related issues 3 (3 open0 closed)

Related to Suricata - Feature #6456: output: binary loggingNewOISF DevActions
Related to Suricata - Feature #2167: eve-ngAssignedJason IshActions
Related to Suricata - Bug #6281: dns: structure of query differs between "alert" and "dns" event typesIn ProgressJason IshActions
Actions #1

Updated by Jason Ish 6 months ago

Actions #2

Updated by Jason Ish 6 months ago

  • Description updated (diff)
Actions #3

Updated by Victor Julien 6 months ago

Actions #4

Updated by Philippe Antoine 4 months ago

  • Related to Bug #6281: dns: structure of query differs between "alert" and "dns" event types added
Actions

Also available in: Atom PDF