-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
eve: revert ethernet addresses when needed #10498
Conversation
EVE logging has a direction parameter that can cause the logging of an application layer to be done in a direction that is not linked to the packet. As a result the source IP addres could be assigned the MAC address of the destination IP and reverse. This patch addresses this by propagating the direction to the ethernet logging function and using it there to define the correct mapping. Issue OISF#6405
It looks like netflow events need a fix. Setting to draft for now. |
Humm suricata-verify needs an update in fact. |
Information: ERROR: QA failed on SURI_TLPW2_autofp_suri_time.
Pipeline 18725 |
dst = p->ethh->eth_dst; | ||
} | ||
break; | ||
case LOG_DIR_FLOW_TOSERVER: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
is this the same as LOG_DIR_FLOW
?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks like it is and could do with // fallthrough
@@ -777,8 +813,14 @@ static int CreateJSONEther(JsonBuilder *js, const Packet *p, const Flow *f) | |||
} | |||
jb_close(info.dst); | |||
jb_close(info.src); | |||
jb_set_object(js, "dest_macs", info.dst); | |||
jb_set_object(js, "src_macs", info.src); | |||
/* case is handling netflow too so may need to revert */ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this looks hacky
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Could you rebase it to get a green CI ?
Rebased in #11197 |
Update of #9651 fixing the formatting.
EVE logging has a direction parameter that can cause the logging of an application layer to be done in a direction that is not linked to the packet. As a result the source IP addres could be assigned the MAC address of the destination IP and reverse.
This patch addresses this by propagating the direction to the ethernet logging function and using it there to define the correct mapping.
Issue #6405
Make sure these boxes are signed before submitting your Pull Request -- thank you.
https://docs.suricata.io/en/latest/devguide/contributing/contribution-process.html
https://suricata.io/about/contribution-agreement/ (note: this is only required once)
Link to redmine ticket: https://redmine.openinfosecfoundation.org/issues/6405
Describe changes:
Provide values to any of the below to override the defaults.
SV_BRANCH=OISF/suricata-verify#1667