Actions
Feature #7347
open
EL
EL
eve/alert: log file_data
Feature #7347:
eve/alert: log file_data
Effort:
Difficulty:
Label:
Description
As transformation occurs on stream data when it becomes file data, it may not be trivial for the analyst to understand why an alert did fire on some file content. To address this problem, we can log the file data in the events to allow an easy analysis.
As file data is mostly binary, logging to base64 should be enough.
VJ Updated by Victor Julien over 1 year ago
- Subject changed from Log file_data in alert events to eve/alert: log file_data
PA Updated by Philippe Antoine over 1 year ago
- Status changed from In Progress to In Review
PA Updated by Philippe Antoine over 1 year ago
Looks like a feature rather than a bug to me...
VJ Updated by Victor Julien 11 months ago
- Tracker changed from Bug to Feature
- Target version changed from TBD to 9.0.0-beta1
PA Updated by Philippe Antoine 6 days ago
- Status changed from In Review to Assigned
Repuuting in assigned state as PR got closed as stale
Actions