Project

General

Profile

Actions

Bug #1324

closed

vlan tag in eve.json

Added by Peter Manev almost 10 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Using Suricata 2.1beta2 - when VLAN tags are present in the traffic - eve.json writes an

event_type:"alert" 

with vlan id but
event_type:"http" 

does not reflect the vlan id at all. The VLAN tag is written only once in the eve.json output instead of once per every event_type present with VLAN ID.

pcap/rule pair privately shared.


Related issues 1 (0 open1 closed)

Related to Suricata - Bug #2057: eve.json flow logs do not contain in_ifaceClosedCommunity TicketActions
Actions

Also available in: Atom PDF