Skip to content

output/alert: rewrite code for app-layer properties#9182

Closed
catenacyber wants to merge 1 commit intoOISF:masterfrom
catenacyber:output-alert-applayer-v9
Closed

output/alert: rewrite code for app-layer properties#9182
catenacyber wants to merge 1 commit intoOISF:masterfrom
catenacyber:output-alert-applayer-v9

Conversation

@catenacyber
Copy link
Contributor

Link to redmine ticket:
None, preliminary work for https://redmine.openinfosecfoundation.org/issues/5053 and app-layer plugins
Part of #8961
Actually there is https://redmine.openinfosecfoundation.org/issues/3827

Describe changes:

  • Fix setup-app-layer script so that it adds app-layer metadata to alerts

After that, there is still from #8961

  • addition of protocols missing alert metadata (like krb5) + behavioral change for dns alert metadata
  • reusing these SimpleTxLogFunc from a JsonGenericLogger to remove many C files

Modifies #9053 by rebasing now that #9052 and its SV counterpart got merged

Especially fix setup-app-layer script to not forget this part
@suricata-qa
Copy link

WARNING:

field baseline test %
SURI_TLPR1_stats_chk
.flow.memuse 592373632 520447704 87.86%

Pipeline 15054

@catenacyber
Copy link
Contributor Author

Rebased in #9252

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Comments