Project

General

Profile

Actions

Task #6084

closed

output/alert: enable logging `PASS` alerts

Added by Juliana Fajardini Reichow over 1 year ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

This should be part of the `alert` event, but allowing to log `pass` rules that triggered.

Will likely involve work related to the alerts queue.


Related issues 1 (0 open1 closed)

Related to Suricata - Bug #5464: eve: if alert and drop rules match for a packet, "alert.action" is ambigiousClosedJuliana Fajardini ReichowActions
Actions #1

Updated by Victor Julien over 1 year ago

  • Related to Bug #5464: eve: if alert and drop rules match for a packet, "alert.action" is ambigious added
Actions #2

Updated by Victor Julien over 1 year ago

  • Priority changed from Low to Normal
  • Target version changed from 7.0.0 to 8.0.0-beta1
Actions #3

Updated by Victor Julien 4 months ago

  • Status changed from Assigned to Closed
  • Assignee deleted (Juliana Fajardini Reichow)
  • Target version deleted (8.0.0-beta1)

I think is implemented as alert then pass in #5466, so closing this.

Actions

Also available in: Atom PDF