Actions
Bug #6983
closedalert/metadata: no pgsql object encapsulation
Affected Versions:
Effort:
Difficulty:
Label:
Description
When adding a fix for #6092 I didn't take into consideration that the EVE object for pgsql
is actually created outside of rs_pgsql_logger
, which leads to the alert
metadata being created without the pgsql
object encapsulation:
"alert": { "action": "allowed", "gid": 1, "signature_id": 1, "rev": 1, "signature": "PGSQL Test Rule", "category": "", "severity": 3 }, "request": { "simple_query": "select * from rules where sid = 2021701;" }, "response": { "field_count": 10, "data_rows": 3, "data_size": 1104, "command_completed": "SELECT 3" },
Now, this must to be fixed.
Actions