New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add missing Suricata schema types and fields #1176
Conversation
Thanks for contributing these definitions! Since you changed the layout, the integration test baseline needs to be updated. (This is why CI fails.) If you invoke Thereafter, CI will be green. |
Thanks for the explanation, will do. It's OK to introduce optional fields where the output might be 'null', right? I did this because, for example, |
Yes, that works. In fact, that's currently how we can have non-breaking updates. The new type can technically be seen as a strict superset of the old type. |
Schema additions have affected the output of some integration test runs. This commit adjusts the expected output to match the new output format after the schema change.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Nice work! 🙏
📔 Description
This PR introduces the currently missing Suricata schema types
nfs
,tftp
,snmp
andikev2
. It also adds correct and consistent types for the common fieldsvlan
andin_iface
.📝 Checklist
🎯 Review Instructions
Please double-check whether the changes correspond to current best practices and whether the schema loads for the relevant VAST versions.