Project

General

Profile

Actions

Feature #8566

open
VJ VJ

firewall: support generating alerts on default policy

Feature #8566: firewall: support generating alerts on default policy

Added by Victor Julien 5 days ago. Updated 1 day ago.

Status:
In Review
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Currently this won't work as the default policy does not have a Signature object.

firewall:
  policies:
    http:
      request-started: [ "accept:hook" ]

      request-body: [ "accept:hook" ]
      request-trailer: [ "accept:hook" ]
      request-complete: [ "accept:tx" ,"alert" ]

Related issues 3 (3 open0 closed)

Related to Suricata - Feature #7701: firewall: configurable default policiesResolvedVictor JulienActions
Related to Suricata - Feature #8479: eve/firewall: dedicated log record typeNewActions
Blocks Suricata - Story #7583: 9.0.0: usecase: improve firewall usecaseAssignedVictor JulienActions
Actions

Also available in: PDF Atom