Conversation
Can you make a ticket for the SSH direction change? As this could be a breaking change on its own. |
Yes, but if it is the right thing to do : We can
Protocols with LOG_DIR_PACKET : BitTorrent, ike, krb5, nfs, quic, rdp, sip, snap, tftp |
Also have to consider those that log requests separate from responses. This is probably where packet direction makes sense. Currently LOG_DIR_FLOW is used for DNS, but it probably shouldn't be. But should still continue to be used for TLS, and SSH for instance. |
|
WARNING:
Pipeline 18073 |
|
Thank you Jason, Continued in #10319 |
Link to redmine tickets:
https://redmine.openinfosecfoundation.org/issues/3827
Preliminary work for https://redmine.openinfosecfoundation.org/issues/5053
Describe changes:
There is one behavior change for SSH switching from
LOG_DIR_PACKETtoLOG_DIR_FLOWWhat do you think about it ?
Should there be 2 functions for
JsonGenericLogger? likeJsonGenericLoggerDirPacketandJsonGenericLoggerDirFlow? So that we do not have any behavioral changesOr should we choose to unify the behavior between the protocols ? And if so, should we choose
LOG_DIR_PACKETorLOG_DIR_FLOW?#10166 rebased
OISF/suricata-verify#1490