Actions
Bug #1324
closedvlan tag in eve.json
Affected Versions:
Effort:
Difficulty:
Label:
Description
Using Suricata 2.1beta2 - when VLAN tags are present in the traffic - eve.json writes an
event_type:"alert"
with vlan id but
event_type:"http"
does not reflect the vlan id at all. The VLAN tag is written only once in the eve.json output instead of once per every event_type present with VLAN ID.
pcap/rule pair privately shared.
Actions