Project

General

Profile

Actions

Bug #4439

closed

eve: log alert direction

Added by Eric Leblond over 3 years ago. Updated about 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

If the alert event contains the flow information it is not possible to know which from the source or the destination IP is the client for the flow.

Actions #1

Updated by Eric Leblond over 3 years ago

  • Status changed from New to In Review
Actions #2

Updated by Odin Jenseg over 3 years ago

Hi Eric,

I think this also would make sense to include this type of information for the event_type=fileinfo, since a fileinfo event can be triggered in both direction.

Actions #3

Updated by Victor Julien about 2 years ago

  • Status changed from In Review to Closed
  • Target version set to 7.0.0-beta1
Actions #4

Updated by Victor Julien about 2 years ago

  • Subject changed from Log data way in alert to eve: log alert direction
Actions

Also available in: Atom PDF