Project

General

Profile

Actions

Bug #5754

open

I use the file-extraction to store the files transferred by HTTP2, but fileinfo does not have the filename field.

Added by YuHan Xu about 2 years ago. Updated about 1 year ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

{"timestamp":"2022-12-09T06:02:08.553120+0000","flow_id":912881598130729,"in_iface":"ens256","event_type":"fileinfo","src_ip":"2.0.1.195","src_port":80,"dest_ip":"1.0.4.75","dest_port":61828,"proto":"TCP","http2":{"version":"2","response_headers":[{"name":":status","value":"200"},{"name":"content-type","value":"image/jpeg"}],"status":200,"http2":{"stream_id":1,"request":{},"response":{}}},"app_proto":"http2","fileinfo":{"sid":[3900017],"magic":"EICAR virus test files","gaps":false,"state":"CLOSED","md5":"44d88612fea8a8f36de82e1278abb02f","sha1":"3395856ce81f2b7382dee72602f798b642f14140","sha256":"275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f","stored":true,"file_id":2,"size":68,"tx_id":1},"host":"suricata"}
My yaml file,pcap and rules have been uploaded.


Files

suricata.yaml (71.2 KB) suricata.yaml YuHan Xu, 12/13/2022 09:25 AM
http2-get.pcap (32.3 KB) http2-get.pcap test pcap YuHan Xu, 12/13/2022 09:26 AM
filestore.rules (667 Bytes) filestore.rules my rules YuHan Xu, 12/13/2022 09:27 AM

Related issues 1 (0 open1 closed)

Related to Suricata - Documentation #5088: file.name sticky buffer is not documentedClosedJason TaylorActions
Actions

Also available in: Atom PDF