Project

General

Profile

Actions

Optimization #6850

closed
JF OD

investigate: overall, some modules may be way more verbose than needed

Optimization #6850: investigate: overall, some modules may be way more verbose than needed

Added by Juliana Fajardini Reichow about 2 years ago. Updated 5 days ago.

Status:
Rejected
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

With stream events, some other fields added from app-layer, we may add way too much data to alert events.

Investigate what truly makes sense, and other modules that also do that.


Related issues 2 (1 open1 closed)

Related to Suricata - Security #6770: log: arbitrary-length value can be loggedClosedOISF DevActions
Related to Suricata - Task #6851: eve/syslog: stats message too long for many default configurationsNewOISF DevActions
Actions

Also available in: PDF Atom