Project

General

Profile

Actions

Feature #8425

open

ntp: add ntp transaction logging

Added by Jason Ish 3 days ago. Updated 1 day ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

NTP is missing a transaction logger. Due to the chattiness of NTP it should probably be disabled by default. The main use case would be for adding NTP metadata to an alert.


Related issues 3 (3 open0 closed)

Related to Suricata - Feature #8429: rules: add ntp.mode keywordNewActions
Related to Suricata - Feature #8430: rules: add ntp.version keywordNewActions
Related to Suricata - Feature #8431: rules: add ntp.stratum keywordNewActions
Actions

Also available in: Atom PDF