Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add new Suricata schema type 'packet' #1819

Merged
merged 3 commits into from Aug 2, 2021
Merged

Conversation

satta
Copy link
Contributor

@satta satta commented Aug 2, 2021

📔 Description

Add a new Suricata schema type 'packet'. this is output as EVE-JSON when the tagged-packets config option is set and a rule tags a packet using, e.g. tag:session,5,packets;. This PR adds schema support for this case, which has not been considered before.

📝 Checklist

  • All user-facing changes have changelog entries.
  • The changes are reflected on docs.tenzir.com/vast, if necessary.
  • The PR description contains instructions for the reviewer, if necessary.

🎯 Review Instructions

Please test with current VAST version, I did not test (i.e. run the test suite) with the latest version due to compiler version issues.

Copy link
Member

@mavam mavam left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the contribution, I just tweaked the changelog entry a bit!

changelog/unreleased/1819.md Outdated Show resolved Hide resolved
Co-authored-by: Matthias Vallentin <matthias@tenzir.com>
@mavam mavam enabled auto-merge August 2, 2021 16:01
@mavam mavam merged commit 6ad5582 into tenzir:master Aug 2, 2021
@satta satta deleted the schema-packet branch August 2, 2021 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants