Commit Graph

19 Commits (e22a833b948a8476d89fc40297404f6e72e830e3)

Author SHA1 Message Date
Maurizio Abba bce7c2dd87 eve/http: add tx->request_port_number as http_port
Add the port specified in the hostname (if any) to the http object in
eve. The port may be different from the dest_port used by the TCP flow.
7 years ago
Pascal Delalande 4f48927c44 doc: spelling mistakes in various sections of the user guide 8 years ago
Pascal Delalande e3c5784dd5 doc: minor updates (tls custom, TODO removal, ftp/smb file rules) 8 years ago
Victor Julien 83bf60d897 doc: add ntlmssp, kerberos and other setup fields 8 years ago
Victor Julien e09027915a doc: fix json formatting in smb doc 8 years ago
Victor Julien 67e81a9555 doc: initial smb eve documentation 8 years ago
Mats Klepsland 47a7ebbbc2 doc: add JA3 fields to the TLS logger documentation 8 years ago
Giuseppe Longo fb66d45754 doc: introduce dns compact logging 8 years ago
Victor Julien 50a182194a eve: log pcap filename 8 years ago
Pascal Delalande 2e5b293afb doc: update eve json output for DNS and HTTP 8 years ago
Pascal Delalande 80f2fbac6e rust/tftp: eve logging with rust 8 years ago
Pascal Delalande 0c99338e07 doc: update docs for DNS flags logging 8 years ago
Eric Leblond ef88689f1e doc: add app_proto to alert event 9 years ago
Eric Leblond f4374ffd0b doc: some more info about alert format 9 years ago
Ray Ruvinskiy 7539973109 tls: logging for session resumption
We assume session resumption has occurred if the Client Hello message
included a session id, we have not seen the server certificate, but
we have seen a Change Cipher Spec message from the server.

Previously, these transactions were not logged at all because the
server cert was never seen.

Ticket: https://redmine.openinfosecfoundation.org/issues/1969
9 years ago
Mats Klepsland ee9f822b8e doc: add documentation for tls_cert_serial keyword 9 years ago
Mats Klepsland e91bb09c91 doc: add documentation for TLS eve-log 9 years ago
Andi 8e655cf107 eve-json-format: add newest version from the wiki
This was added by pevma in the wiki, so should go into the sphinx doc as well.
9 years ago
Jason Ish 2751baae46 doc: rename from "sphinx" to "userguide" 9 years ago