Actions
Feature #8479
open
VJ
eve/firewall: dedicated log record type
Feature #8479:
eve/firewall: dedicated log record type
Effort:
Difficulty:
Label:
Description
Currently the firewall mode rules are not logging by default, but can use the alert keyword to generate an alert when they match. This produces the rich alert record type.
It may be worth considering a more dedicated type, that includes the drop record type info as well as detailed info about states, etc.
VJ Updated by Victor Julien 2 days ago
- Related to Feature #8456: firewall: Add source engine field to alert/drop events to distinguish firewall from IDS/IPS alerts added
VJ Updated by Victor Julien 2 days ago
- Related to Feature #8480: firewall: allow specifying multiple actions added
Actions