unified2: remove deprecated output unified2

Ticket 2385:
https://redmine.openinfosecfoundation.org/issues/2385
pull/4605/head
Jason Ish 7 years ago committed by Victor Julien
parent bfe3c0105d
commit d86973b386

@ -490,13 +490,6 @@
[AC_MSG_ERROR([clang needed to build ebpf files])])
])
# enable workaround for old barnyard2 for unified alert output
AC_ARG_ENABLE(old-barnyard2,
AS_HELP_STRING([--enable-old-barnyard2], [Use workaround for old barnyard2 in unified2 output]),[enable_old_barnyard2=$enableval],[enable_old_barnyard2=no])
AS_IF([test "x$enable_old_barnyard2" = "xyes"], [
AC_DEFINE([HAVE_OLD_BARNYARD2],[1],[Use workaround for old barnyard2 in unified2 output])
])
# enable debug output
AC_ARG_ENABLE(debug,
AS_HELP_STRING([--enable-debug], [Enable debug output]),[enable_debug=$enableval],[enable_debug=no])

@ -12,7 +12,6 @@ alert-debuglog.c alert-debuglog.h \
alert-fastlog.c alert-fastlog.h \
alert-prelude.c alert-prelude.h \
alert-syslog.c alert-syslog.h \
alert-unified2-alert.c alert-unified2-alert.h \
app-layer.c app-layer.h \
app-layer-dcerpc.c app-layer-dcerpc.h \
app-layer-dcerpc-udp.c app-layer-dcerpc-udp.h \

File diff suppressed because it is too large Load Diff

@ -1,50 +0,0 @@
/* Copyright (C) 2007-2014 Open Information Security Foundation
*
* You can copy, redistribute or modify this Program under the terms of
* the GNU General Public License version 2 as published by the Free
* Software Foundation.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
*
* You should have received a copy of the GNU General Public License
* version 2 along with this program; if not, write to the Free Software
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
* 02110-1301, USA.
*/
/**
* \file
* \author Breno Silva <breno.silva@gmail.com>
*/
#ifndef __ALERT_UNIFIED2_ALERT_H__
#define __ALERT_UNIFIED2_ALERT_H__
/** Unified2 Option packet action */
#define UNIFIED2_PACKET_FLAG 1
#define UNIFIED2_BLOCKED_FLAG 0x20
/** Unified2 Header Types */
#define UNIFIED2_EVENT_TYPE 1
#define UNIFIED2_PACKET_TYPE 2
#define UNIFIED2_IDS_EVENT_TYPE 7
#define UNIFIED2_EVENT_EXTENDED_TYPE 66
#define UNIFIED2_PERFORMANCE_TYPE 67
#define UNIFIED2_PORTSCAN_TYPE 68
#define UNIFIED2_IDS_EVENT_IPV6_TYPE 72
#define UNIFIED2_IDS_EVENT_MPLS_TYPE 99
#define UNIFIED2_IDS_EVENT_IPV6_MPLS_TYPE 100
#define UNIFIED2_IDS_EVENT_EXTRADATA_TYPE 110
#define UNIFIED2_EXTRADATA_CLIENT_IPV4_TYPE 1
#define UNIFIED2_EXTRADATA_CLIENT_IPV6_TYPE 2
#define UNIFIED2_EXTRADATA_TYPE_BLOB 1
#define UNIFIED2_EXTRADATA_TYPE_EXTRA_DATA 4
void Unified2AlertRegister(void);
OutputInitResult Unified2AlertInitCtx(ConfNode *);
#endif /* __ALERT_UNIFIED2_ALERT_H__ */

@ -41,7 +41,6 @@
#include "output.h"
#include "alert-fastlog.h"
#include "alert-unified2-alert.h"
#include "alert-debuglog.h"
#include "alert-prelude.h"
#include "alert-syslog.h"
@ -1099,8 +1098,6 @@ void OutputRegisterLoggers(void)
AlertPreludeRegister();
/* syslog log */
AlertSyslogRegister();
/* unified2 log */
Unified2AlertRegister();
/* drop log */
LogDropLogRegister();
JsonDropLogRegister();

@ -42,7 +42,6 @@
#include "alert-fastlog.h"
#include "alert-prelude.h"
#include "alert-unified2-alert.h"
#include "alert-debuglog.h"
#include "flow-bypass.h"

@ -42,7 +42,6 @@
#include "alert-fastlog.h"
#include "alert-prelude.h"
#include "alert-unified2-alert.h"
#include "alert-debuglog.h"
#include "util-debug.h"

@ -43,7 +43,6 @@
#include "alert-fastlog.h"
#include "alert-prelude.h"
#include "alert-unified2-alert.h"
#include "alert-debuglog.h"
#include "log-httplog.h"

@ -38,7 +38,6 @@
#include "alert-fastlog.h"
#include "alert-prelude.h"
#include "alert-unified2-alert.h"
#include "alert-debuglog.h"
#include "util-debug.h"

@ -287,12 +287,6 @@ outputs:
# flowints.
#- metadata
# deprecated - unified2 alert format for use with Barnyard2
- unified2-alert:
enabled: no
# for further options see:
# https://suricata.readthedocs.io/en/suricata-5.0.0/configuration/suricata-yaml.html#alert-output-for-use-with-barnyard2-unified2-alert
# a line based log of HTTP requests (no alerts)
- http-log:
enabled: no

Loading…
Cancel
Save