Project

General

Profile

Actions

Bug #7347

open

eve/alert: log file_data

Added by Eric Leblond 6 days ago. Updated 4 days ago.

Status:
In Progress
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

As transformation occurs on stream data when it becomes file data, it may not be trivial for the analyst to understand why an alert did fire on some file content. To address this problem, we can log the file data in the events to allow an easy analysis.

As file data is mostly binary, logging to base64 should be enough.

Actions

Also available in: Atom PDF