Actions
Bug #7569
closedlogging: Mac addresses are not logged for pkt_src detect/log or flow timeout
Affected Versions:
Effort:
Difficulty:
Label:
Description
Cf https://forum.suricata.io/t/some-mac-addresses-are-missing-in-the-http-logs/5389/2
Not sure if we will want to backport this
Check with jq 'select(.ether == null)' log/eve.json
and having ethernet: yes
in suricata.yaml
Updated by Shivani Bhardwaj about 1 month ago
Q: Why should a pseudo pkt carry information like MAC address?
Updated by Philippe Antoine about 1 month ago
In the case mentioned, it belong to a flow
Updated by Philippe Antoine about 1 month ago
- Status changed from New to Rejected
Indeed duplicate of #5486 cf https://redmine.openinfosecfoundation.org/issues/5486#note-5
Thanks Victor for catching it
Actions