Task #6463
open
eve/output: investigate how to track coverage / parity
Added by Juliana Fajardini Reichow 6 months ago.
Updated 6 months ago.
Description
We want to find a reliable and efficient way to track the outputs that we have on eve, to ensure they're
consistent and that we have everything represented in our JSON schema.
Related issues
3 (3 open — 0 closed)
- Related to Task #6443: Suricon 2023 brainstorm added
- Subject changed from outputs: investigate how to track coverage / parity to eve/output: investigate how to track coverage / parity
This also relates to ensuring that for each protocol, there are no logging discrepancies when we log a field in an alert and in an event, for instance.
- Related to Task #4772: tracking: parity between fields logged and fields available for detection added
Also available in: Atom
PDF