Project

General

Profile

Actions

Feature #7101

open

eve: add number of flowbits in protocol records and alerts

Added by Peter Manev 5 months ago. Updated 4 months ago.

Status:
Feedback
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Very useful for hunting can be the number of flowbits present in a protocol log or alert.
Details: https://www.stamus-networks.com/blog/suricata-threat-hunting-fundamentals.

The suggestion is to have a simple key/value added to the JSON logs indicating number of flowbits present.
This can also be achieved via SIEM aggregations but if present in the logs it enables for more detection formulas and mechanisms.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #2167: tracking: eve enhancementsNewOISF DevActions
Actions

Also available in: Atom PDF