Feature #7532
closeddetect/ldap: add keywords for LDAPResult
Description
Add keyword ldap.responses.result_code to match on the LDAPResult field resultCode which is an enum
Add keyword ldap.responses.message to match on the LDAPResult field errorMessage which is an octet string
Eve fields to match:
ldap.responses[].bind_response.result_code
ldap.responses[].bind_response.message
ldap.responses[].search_result_done.result_code
ldap.responses[].search_result_done.message
ldap.responses[].modify_response.result_code
ldap.responses[].modify_response.message
ldap.responses[].add_response.result_code
ldap.responses[].add_response.message
ldap.responses[].del_response.result_code
ldap.responses[].del_response.message
ldap.responses[].mod_dn_response.result_code
ldap.responses[].mod_dn_response.message
ldap.responses[].compare_response.result_code
ldap.responses[].compare_response.message
ldap.responses[].extended_response.result_code
ldap.responses[].extended_response.message
AD Updated by Alice da Silva Akaki about 1 year ago
- Description updated (diff)
PA Updated by Philippe Antoine about 1 year ago
- Blocks Task #7452: ldap: add keywords to match output added
PA Updated by Philippe Antoine about 1 year ago
There is no ldap.request.result_code it is only in responses right ?
AD Updated by Alice da Silva Akaki about 1 year ago
- Description updated (diff)
AD Updated by Alice da Silva Akaki about 1 year ago
Philippe Antoine wrote in #note-3:
There is no ldap.request.result_code it is only in responses right ?
yes, it is fixed now
AD Updated by Alice da Silva Akaki about 1 year ago
- Status changed from New to In Progress
PRs for review:
SU: https://github.com/OISF/suricata/pull/12555
SV: https://github.com/OISF/suricata-verify/pull/2282
PA Updated by Philippe Antoine about 1 year ago
- Status changed from In Progress to In Review
AD Updated by Alice da Silva Akaki about 1 year ago
- Description updated (diff)
AD Updated by Alice da Silva Akaki about 1 year ago
- Subject changed from detect: add keywords for LDAPResult to detect/ldap: add keywords for LDAPResult
PA Updated by Philippe Antoine about 1 year ago
- Target version changed from 8.0.0 to 8.0.0-beta1
AD Updated by Alice da Silva Akaki about 1 year ago
- Status changed from In Review to Closed