Task #6463
open
eve/output: investigate how to track coverage / parity
Added by Juliana Fajardini Reichow 12 months ago.
Updated 12 months ago.
Description
We want to find a reliable and efficient way to track the outputs that we have on eve, to ensure they're
consistent and that we have everything represented in our JSON schema.
Related issues
4 (4 open — 0 closed)
- Related to Task #6443: Suricon 2023 brainstorm added
- Subject changed from outputs: investigate how to track coverage / parity to eve/output: investigate how to track coverage / parity
This also relates to ensuring that for each protocol, there are no logging discrepancies when we log a field in an alert and in an event, for instance.
- Related to Task #4772: tracking: parity between fields logged and fields available for detection added
- Blocks Story #6597: rules: improve rules keyword/output parity added
Also available in: Atom
PDF