[Oisf-users] eve fields per event type

Brian Kellogg theflakes at gmail.com
Fri Oct 12 13:23:12 UTC 2018


I'm using the below link to understand Eve log format and data types.

https://suricata.readthedocs.io/en/latest/output/eve/eve-json-format.html

I see with 4.1 there are several changes coming for logging. Also seeing
that all fields my not be listed in the above link.

Is there a comprehensive list of all event type logs and their possible
fields and changes forth coming in 4.1? I can chew through the code if I
need to.

Is there an estimated release date for 4.1? I know this is all devs
favorite question so feel free to yell at me.

If documentation is missing may I submit my findings anywhere to help out
with this? Not sure if my discovery will be useful for others but I may be
able to work around that.

I apologize for any of my ignorance, new to Suricata logging.

thanks
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20181012/07c8b231/attachment.html>


More information about the Oisf-users mailing list