doc: fixed remaining FIXME

pull/2302/head
Andreas Herz 10 years ago committed by Victor Julien
parent 715485a42b
commit 347e3b4972

@ -276,9 +276,9 @@ integration with tools like logstash.
#- drop
- ssh
For more advanced configuration options, see [[**FIXME** EveJSONOutput]].
.. FIXME jsonformat ref
The format is documented in :ref:`Eve JSON Format <Eve JSON Format>`
For more advanced configuration options, see :ref:`Eve JSON Output <eve-json-output>`.
The format is documented in :ref:`Eve JSON Format <eve-json-format>`.
Log output for use with Barnyard (unified.log)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
@ -350,7 +350,7 @@ This log keeps track of all HTTP-traffic events. It contains the HTTP
request, hostname, URI and the User-Agent. This information will be
stored in the http.log (default name, in the suricata log
directory). This logging can also be performed through the use of the
[[**FIXME** EveJSONFormat|Eve-log capability]].
:ref:`Eve-log capability <eve-json-format>`.
Example of a HTTP-log line with non-extended logging:
@ -384,7 +384,7 @@ This log keeps track of all DNS events (queries and replies). It
contains the type of DNS activity that has been performed, the
requested / replied domain name and relevant data suck as client,
server, ttl, resource record data. This logging can also be performed
through the use of the [[EveJSONFormat|Eve-log capability]] which
through the use of the :ref:`Eve-log capability <eve-json-format>` which
offers easier parsing.
Example of the apperance of a DNS log of a query with a preceding reply:

Binary file not shown.

@ -1,3 +1,5 @@
.. _eve-json-format:
Eve JSON Format
===============

@ -1,3 +1,5 @@
.. _eve-json-output:
Eve JSON Output
===============

@ -41,7 +41,7 @@ Make sure your Suricata is compiled/installed with libjansson support enabled:
CUDA enabled: no
...
If it isn't check out the [[**FIXME** Suricata_installation]] page to install or compile Suricata for your distribution.
If it isn't check out the `Suricata Installation <https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Suricata_Installation>`_ page to install or compile Suricata for your distribution.
**NOTE:** you will need these packages installed -> **libjansson4** and *libjansson-dev* before compilation.
Configure suricata

@ -228,9 +228,7 @@ The first example illustrates a signature which searches for byte 512
of the payload. The second example illustrates a signature searching
for byte 50 after the last match.
You can also use the negation (!) before isdataat. Suricata does not
support using it yet, but will support it in future versions of the
engine. For more information see **fixme: what is this supposed to link to**.
You can also use the negation (!) before isdataat.
.. image:: payload-keywords/isdataat1.png

@ -79,10 +79,6 @@ Suricata has its own specific pcre modifiers. These are:
relative to the previous match so both matches have to be in the
HTTP-raw-uri buffer. Read more about :doc:`http-uri-normalization`.
** FIXME - image is missing on wiki: .. image:: pcre/pcre7.png
** FIXME - image is missing on wiki: .. image:: pcre/pcre8.png
* ``P``: Makes pcre match on the HTTP- request-body. So, it matches on
the same buffer as http_client_body. P can be combined with /R. Note
that R is relative to the previous match so both matches have to be

Loading…
Cancel
Save