Skip to content

Comments

Output alert applayer v3#8884

Closed
catenacyber wants to merge 29 commits intoOISF:masterfrom
catenacyber:output-alert-applayer-v3
Closed

Output alert applayer v3#8884
catenacyber wants to merge 29 commits intoOISF:masterfrom
catenacyber:output-alert-applayer-v3

Conversation

@catenacyber
Copy link
Contributor

@catenacyber catenacyber commented May 15, 2023

Link to redmine ticket:
None, preliminary work for https://redmine.openinfosecfoundation.org/issues/5053 and app-layer plugins
Continuation of #8772

Describe changes:

  • Fix setup-app-layer script so that it adds app-layer metadata to alerts
  • Adds ftp metadata to alerts
  • Adds tftp metadata to alerts
  • Adds krb5 metadata to alerts

Continues #8872 by having JsonGenericLogger to remove more boilerplate C code

SV_BRANCH=pr/1196

OISF/suricata-verify#1196

Still to do :

  • Create tickets for missing protocols : pgsql, dcerpc, dhcp,

@codecov
Copy link

codecov bot commented May 15, 2023

Codecov Report

Merging #8884 (81733d6) into master (13fe957) will decrease coverage by 0.07%.
The diff coverage is 97.10%.

❗ Current head 81733d6 differs from pull request most recent head 8252ae7. Consider uploading reports for the commit 8252ae7 to get more accurate results

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #8884      +/-   ##
==========================================
- Coverage   82.30%   82.24%   -0.07%     
==========================================
  Files         969      957      -12     
  Lines      273240   272798     -442     
==========================================
- Hits       224902   224366     -536     
- Misses      48338    48432      +94     
Flag Coverage Δ
fuzzcorpus 64.63% <84.97%> (+0.01%) ⬆️
suricata-verify 60.24% <97.10%> (-0.13%) ⬇️
unittests 63.06% <23.69%> (+0.10%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

@suricata-qa
Copy link

Information:

field baseline test %
TREX_GENERIC_stats_chk
.capture.kernel_drops 0 895 0.00

Pipeline 13787

@suricata-qa
Copy link

WARNING:

field baseline test %
build_asan

Pipeline 13789

@suricata-qa
Copy link

WARNING:

field baseline test %
build_asan

Pipeline 13790

@catenacyber catenacyber force-pushed the output-alert-applayer-v3 branch from 49957a3 to 9fa961e Compare May 15, 2023 14:51
@catenacyber
Copy link
Contributor Author

Does it make sense for bug-4903 to test for ssh tx id ? I think not...

@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 13791

@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 13794

@catenacyber catenacyber force-pushed the output-alert-applayer-v3 branch from 8d339f2 to 958d65c Compare May 16, 2023 07:30
@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 13797

@catenacyber catenacyber force-pushed the output-alert-applayer-v3 branch from 958d65c to 81733d6 Compare May 16, 2023 10:12
@catenacyber catenacyber force-pushed the output-alert-applayer-v3 branch from 81733d6 to 8252ae7 Compare May 16, 2023 12:43
@suricata-qa
Copy link

Information: QA ran without warnings.

Pipeline 13807

@catenacyber
Copy link
Contributor Author

Replaced by #8893

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants