Project

General

Profile

Actions

Task #6463

open

eve/output: investigate how to track coverage / parity

Added by Juliana Fajardini Reichow about 1 year ago. Updated about 1 year ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Outreachy

Description

We want to find a reliable and efficient way to track the outputs that we have on eve, to ensure they're
consistent and that we have everything represented in our JSON schema.


Related issues 4 (4 open0 closed)

Related to Suricata - Task #6443: Suricon 2023 brainstormAssignedVictor JulienActions
Related to Suricata - Documentation #6478: schema: add missing fieldsNewCommunity TicketActions
Related to Suricata - Task #4772: tracking: parity between fields logged and fields available for detectionAssignedVictor JulienActions
Blocks Suricata - Story #6597: rules: improve rules keyword/output parityNewVictor JulienActions
Actions #1

Updated by Juliana Fajardini Reichow about 1 year ago

  • Related to Task #6443: Suricon 2023 brainstorm added
Actions #2

Updated by Juliana Fajardini Reichow about 1 year ago

  • Subject changed from outputs: investigate how to track coverage / parity to eve/output: investigate how to track coverage / parity

This also relates to ensuring that for each protocol, there are no logging discrepancies when we log a field in an alert and in an event, for instance.

Actions #3

Updated by Victor Julien about 1 year ago

Actions #4

Updated by Juliana Fajardini Reichow about 1 year ago

  • Related to Task #4772: tracking: parity between fields logged and fields available for detection added
Actions #5

Updated by Juliana Fajardini Reichow 3 months ago

  • Blocks Story #6597: rules: improve rules keyword/output parity added
Actions

Also available in: Atom PDF