-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
userguide: document flow_id, with examples - v2 #9785
Conversation
Flow_id explanation expanded from version shared by Peter Manev. Task OISF#6445
Codecov Report
Additional details and impacted files@@ Coverage Diff @@
## master #9785 +/- ##
==========================================
- Coverage 82.40% 82.40% -0.01%
==========================================
Files 968 968
Lines 273871 273871
==========================================
- Hits 225695 225690 -5
- Misses 48176 48181 +5
Flags with carried forward coverage won't be shown. Click here to find out more. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Mostly looks good. :) Some questions inline looking at it as a user.
following fileinfo, :ref:`http<eve-format-http>`, :ref:`anomaly<eve-format-anomaly>` | ||
and :ref:`flow<eve-format-flow>` events, all easily correlated by using the ``flow_id`` EVE field:: | ||
|
||
{ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Perhaps a jq
command here to get this would make sense?
"dest_port": 80 | ||
} | ||
} | ||
{ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should we have all the events in diff boxes? They're a bit difficult to read as a big text
{"timestamp":"2009-11-24T21:27:09.534255","event_type":"TYPE", ...tuple... ,"TYPE":{ ... type specific content ... }} | ||
{"timestamp":"2009-11-24T21:27:09.534255","flow_id":ID_NUMBER, "event_type":"TYPE", ...tuple... ,"TYPE":{ ... type specific content ... }} | ||
|
||
Flow id |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should this be Flow ID
or flow_id
?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Important question. Looking through some other cases, I see that we have ftp_data
as FTP_DATA
, so I'd say it should be flow_id
. Thanks!
Feedback incorporated in: #9790 |
Flow_id explanation expanded from version shared by Peter Manev.
Link to redmine ticket:
https://redmine.openinfosecfoundation.org/issues/6445
Previous PR: #9784
Describe changes:
Result can be seen at: https://suri-rtd-test.readthedocs.io/en/doc-flow-id-v2/output/eve/eve-json-format.html#flow-id
The example part is a bit big, but seemed to make sense that we would include at least some different event types, to illustrate the usage.