Project

General

Profile

Actions

Feature #8479

open
VJ

eve/firewall: dedicated log record type

Feature #8479: eve/firewall: dedicated log record type

Added by Victor Julien 2 days ago.

Status:
New
Priority:
Normal
Assignee:
-
Target version:
Effort:
Difficulty:
Label:

Description

Currently the firewall mode rules are not logging by default, but can use the alert keyword to generate an alert when they match. This produces the rich alert record type.

It may be worth considering a more dedicated type, that includes the drop record type info as well as detailed info about states, etc.


Related issues 2 (2 open0 closed)

Related to Suricata - Feature #8456: firewall: Add source engine field to alert/drop events to distinguish firewall from IDS/IPS alertsNewActions
Related to Suricata - Feature #8480: firewall: allow specifying multiple actionsNewActions

VJ Updated by Victor Julien 2 days ago Actions #1

  • Related to Feature #8456: firewall: Add source engine field to alert/drop events to distinguish firewall from IDS/IPS alerts added

VJ Updated by Victor Julien 2 days ago Actions #2

  • Related to Feature #8480: firewall: allow specifying multiple actions added
Actions

Also available in: PDF Atom