Skip to content

Comments

Output alert applayer v2#8872

Closed
catenacyber wants to merge 10 commits intoOISF:masterfrom
catenacyber:output-alert-applayer-v2
Closed

Output alert applayer v2#8872
catenacyber wants to merge 10 commits intoOISF:masterfrom
catenacyber:output-alert-applayer-v2

Conversation

@catenacyber
Copy link
Contributor

@catenacyber catenacyber commented May 12, 2023

Link to redmine ticket:
None, preliminary work for https://redmine.openinfosecfoundation.org/issues/5053 and app-layer plugins
Continuation of #8772

Describe changes:

  • Fix setup-app-layer script so that it adds app-layer metadata to alerts
  • Adds ftp metadata to alerts
  • Adds tftp metadata to alerts
  • Adds krb5 metadata to alerts

Continues #8864 by incorporating more protocols : Mqtt, rfb, snmp and krb5 (which was not there before)

SV_BRANCH=pr/1196

OISF/suricata-verify#1196

Still to do :

  • finish to list remaining protocols
  • Create tickets for missing protocols : pgsql, dcerpc, dhcp,
  • A next iteration can have JsonGenericLogger to replace all JsonBitTorrentDHTLogger and remove output-json-bittorrent-dht.c

@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 13768

@catenacyber catenacyber force-pushed the output-alert-applayer-v2 branch from bf2284d to cf06719 Compare May 14, 2023 13:54
@codecov
Copy link

codecov bot commented May 14, 2023

Codecov Report

Merging #8872 (cf06719) into master (13fe957) will decrease coverage by 0.13%.
The diff coverage is 95.77%.

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #8872      +/-   ##
==========================================
- Coverage   82.30%   82.18%   -0.13%     
==========================================
  Files         969      969              
  Lines      273240   273222      -18     
==========================================
- Hits       224902   224558     -344     
- Misses      48338    48664     +326     
Flag Coverage Δ
fuzzcorpus 64.40% <85.91%> (-0.21%) ⬇️
suricata-verify 60.30% <95.77%> (-0.07%) ⬇️
unittests 62.98% <0.00%> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 13781

@catenacyber
Copy link
Contributor Author

Replaced by #8884

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants