Actions
Feature #7101
openeve: add number of flowbits in protocol records and alerts
Effort:
Difficulty:
Label:
Description
Very useful for hunting can be the number of flowbits present in a protocol log or alert.
Details: https://www.stamus-networks.com/blog/suricata-threat-hunting-fundamentals.
The suggestion is to have a simple key/value added to the JSON logs indicating number of flowbits present.
This can also be achieved via SIEM aggregations but if present in the logs it enables for more detection formulas and mechanisms.
Updated by Jason Ish about 1 year ago
- Related to Task #2167: tracking: eve enhancements added
Updated by Jason Ish about 1 year ago
Would probably make sense to add for xbits, etc.
Elastic does have the value_count
agg though.
Updated by Lukas Sismis about 1 year ago
- Status changed from New to Feedback
- Assignee changed from OISF Dev to Peter Manev
Updated by Victor Julien 12 months ago
- Subject changed from add number of flowbits in protocol JSON logs and alerts to eve: add number of flowbits in protocol records and alerts
Actions