Project

General

Profile

Actions

Bug #6973

closed
JF PA

detect: log relevant frames app-layer metdata

Bug #6973: detect: log relevant frames app-layer metdata

Added by Juliana Fajardini Reichow almost 2 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Proposed patch already exists (cf https://github.com/OISF/suricata/pull/10924), but was suggested that it had its own ticket


Subtasks 2 (0 open2 closed)

Bug #6974: detect: log relevant frames app-layer metdata (6.0.x backport)RejectedPhilippe AntoineActions
Bug #6975: detect: log relevant frames app-layer metdata (7.0.x backport)ClosedPhilippe AntoineActions

Related issues 2 (0 open2 closed)

Related to Suricata - Bug #6846: eve/alerts: wrongly using tx id 0 when there is no txClosedPhilippe AntoineActions
Related to Suricata - Security #6900: http2: timeout logging headersClosedPhilippe AntoineActions

JF Updated by Juliana Fajardini Reichow almost 2 years ago Actions #1

  • Related to Bug #6846: eve/alerts: wrongly using tx id 0 when there is no tx added

OT Updated by OISF Ticketbot almost 2 years ago Actions #2

  • Subtask #6974 added

OT Updated by OISF Ticketbot almost 2 years ago Actions #3

  • Label deleted (Needs backport to 6.0)

OT Updated by OISF Ticketbot almost 2 years ago Actions #4

  • Subtask #6975 added

OT Updated by OISF Ticketbot almost 2 years ago Actions #5

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine almost 2 years ago Actions #6

Current master situation :
app-layer data does not get logged for frames, since commit 2b4e10224eaebb613352e9b82556b60035d032a1
Before that, and in main7, app-layer data gets logged, but we log tx id 0 if no specific tx was specified.

Also, the lack of tests suggest that there are many protocols which do not set the tx id for their frames...
Which may be due to the unfriendliness of the rust API to create anew frame with a known tx id...

PA Updated by Philippe Antoine almost 2 years ago Actions #7

  • Status changed from New to In Progress

PA Updated by Philippe Antoine almost 2 years ago Actions #8

  • Status changed from In Progress to In Review

PA Updated by Philippe Antoine almost 2 years ago Actions #9

PA Updated by Philippe Antoine almost 2 years ago Actions #10

  • Status changed from In Review to Resolved

PA Updated by Philippe Antoine almost 2 years ago Actions #11

  • Status changed from Resolved to Closed

VJ Updated by Victor Julien almost 2 years ago Actions #12

  • Private changed from Yes to No
Actions

Also available in: PDF Atom