Project

General

Profile

Actions

Bug #4881

closed

alert event incorrectly log stored files

Added by Eric Leblond almost 3 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

When an alert is using filestore, the stored files are not marked as such:

   "files": [
    {
      "sid": [
        3
      ],
      "tx_id": 0,
      "gaps": false,
      "size": 1188,
      "state": "UNKNOWN",
      "filename": "/~lds/b.apkg",
      "stored": false
    }
  ],


Related issues 1 (0 open1 closed)

Has duplicate Suricata - Bug #2500: stored will always equal false in fileinfo eventsClosedElazar BroadActions
Actions

Also available in: Atom PDF