Project

General

Profile

Actions

Bug #7630

open

eve/alert: incorrect verdict with pass + alert rule

Added by Jesse Lepich 7 months ago. Updated about 17 hours ago.

Status:
Feedback
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

This rule:

pass tls $HOME_NET any -> any any (alert; tls.sni; content:"checkip.amazonaws.com"; sid:202502272;)

produces an alert log entry with a verdict of "alert" instead of "pass":

"verdict": {"action": "alert"},


Subtasks 2 (2 open0 closed)

Bug #7906: eve/alert: incorrect verdict with pass + alert rule (7.0.x backport)AssignedJuliana Fajardini ReichowActions
Bug #7911: eve/alert: incorrect verdict with pass + alert rule (8.0.x backport)AssignedJuliana Fajardini ReichowActions
Actions

Also available in: Atom PDF