Project

General

Profile

Actions

Feature #1872

open

add --list-decoder-protos or similar

Added by Peter Manev about 8 years ago. Updated over 4 years ago.

Status:
Assigned
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

It would be useful to have

suricata --list-decoder-protos

or similar to list supported decoder protocols like we have :

pevma@DONPEDRO:~$ sudo suricata --list-app-layer-protos
=========Supported App Layer Protocols=========
http
ftp
smtp
tls
ssh
imap
msn
smb
dcerpc
dns


Related issues 1 (1 open0 closed)

Related to Suricata - Bug #635: Some keywords missing in list-keyword command (like 'tcp-pkt')AssignedOISF DevActions
Actions #1

Updated by Andreas Herz about 8 years ago

  • Assignee set to OISF Dev
  • Target version set to TBD
Actions #2

Updated by Andreas Herz over 5 years ago

  • Related to Bug #635: Some keywords missing in list-keyword command (like 'tcp-pkt') added
Actions #3

Updated by Victor Julien over 5 years ago

  • Status changed from New to Assigned
  • Assignee changed from OISF Dev to Andreas Herz
Actions #4

Updated by Andreas Herz over 5 years ago

While the app-layer-protocols are also keywords usable in rules not all decode protos are real keywords (vlan, pppoe f or example), so should we still print it the same way?

Actions #5

Updated by Peter Manev over 5 years ago

Maybe have a message per field that is not a keyword? could be messy though.

Actions #6

Updated by Victor Julien over 5 years ago

I think these are different things. We have protocols that suri can decode and protocol names for in rules. I don't mind having 2 options to list each set.

Actions #7

Updated by Andreas Herz over 5 years ago

Just to be sure, you would suggest to split those into two options like --list-decoder-protos and --list-decoder-protos-keywords (names still to be discussed)?

Actions #8

Updated by Victor Julien over 5 years ago

Yeah. I would think --list-decoder-protos and --list-rule-protos

Actions #9

Updated by Peter Manev over 5 years ago

I like that approach.

Actions #10

Updated by Andreas Herz about 5 years ago

I can implement that but --list-decoder-protos would still have all and --list-rule-protos would be a subset excluding those which aren't keywords. But while playing around with #635 I would either add those of the --list-rule-protos to the --list-keywords list (to match idea 1) or as a section (to match idea 2).

Actions #11

Updated by Victor Julien over 4 years ago

I'm confused with what you're asking/saying, but I think its best to start with an implementation and then we can discuss the result/output. It's not a big project so it won't be a waste of time if things need to change.

Actions

Also available in: Atom PDF