-
Notifications
You must be signed in to change notification settings - Fork 190
new alert_json plugin with kafka capabilities #88
base: master
Are you sure you want to change the base?
Commits on Mar 28, 2013
-
Created alert_json output plugin skeleton, and integrated in banyard2.
modified: src/output-plugins/Makefile.am modified: src/plugbase.c new file: src/output-plugins/spo_alert_json.c new file: src/output-plugins/spo_alert_json.h
root committedMar 28, 2013 Configuration menu - View commit details
-
Copy full SHA for c5efa08 - Browse repository at this point
Copy the full SHA c5efa08View commit details
Commits on Apr 3, 2013
-
Changed names under spo_alert_json. No funtionality changed except de…
…fault output names modified: output-plugins/spo_alert_json.c
root committedApr 3, 2013 Configuration menu - View commit details
-
Copy full SHA for db69fcf - Browse repository at this point
Copy the full SHA db69fcfView commit details -
Timestamp now printed in milisenconds, instead of string
root committedApr 3, 2013 Configuration menu - View commit details
-
Copy full SHA for eb71ecc - Browse repository at this point
Copy the full SHA eb71eccView commit details -
Each data type add it's own string to a json file now.
root committedApr 3, 2013 Configuration menu - View commit details
-
Copy full SHA for ec29434 - Browse repository at this point
Copy the full SHA ec29434View commit details -
FIXED: JSON invalid fields are not written at all. Before, a ",," was…
… printed modified: output-plugins/spo_alert_json.c
root committedApr 3, 2013 Configuration menu - View commit details
-
Copy full SHA for 25ca718 - Browse repository at this point
Copy the full SHA 25ca718View commit details
Commits on Apr 5, 2013
-
added output-plugins/spo_alert_json.h in src/plugbase.c
modified: src/plugbase.c
root committedApr 5, 2013 Configuration menu - View commit details
-
Copy full SHA for 0df4cdd - Browse repository at this point
Copy the full SHA 0df4cddView commit details -
Added kafka libraries and header (in a future we will add the entire
librdkafka) modified: Makefile.am new file: output-plugins/kafka/librdkafka.a new file: output-plugins/kafka/rdkafka.h new file: output-plugins/librdkafka.a
root committedApr 5, 2013 Configuration menu - View commit details
-
Copy full SHA for df547e1 - Browse repository at this point
Copy the full SHA df547e1View commit details
Commits on Apr 16, 2013
-
Added kafka output to spo_alert_json. Topic is need to know in compile
time, next commit will fix that. Created sfutil/sf_kafka, to send kafka messages. Modify some makefile.am and added -lz, -lrt and -lpthread c flags, needed by kafka. Added rdkafka library too. modified: Makefile.am modified: output-plugins/spo_alert_json.c modified: sfutil/Makefile.am new file: sfutil/kafka/librdkafka.a new file: sfutil/kafka/rd.h new file: sfutil/kafka/rdaddr.h new file: sfutil/kafka/rdcrc32.h new file: sfutil/kafka/rdfile.h new file: sfutil/kafka/rdgz.h new file: sfutil/kafka/rdkafka.h new file: sfutil/kafka/rdrand.h new file: sfutil/kafka/rdtime.h new file: sfutil/kafka/rdtypes.h new file: sfutil/sf_kafka.c new file: sfutil/sf_kafka.h
root committedApr 16, 2013 Configuration menu - View commit details
-
Copy full SHA for 0de1baa - Browse repository at this point
Copy the full SHA 0de1baaView commit details -
Kafka topic can be specified adding a '@' after broker's name
modified: output-plugins/spo_alert_json.c
root committedApr 16, 2013 Configuration menu - View commit details
-
Copy full SHA for c408120 - Browse repository at this point
Copy the full SHA c408120View commit details
Commits on Apr 18, 2013
-
FIX: alert_json can send alerts to a file and a kafka broker at the same
time now modified: output-plugins/spo_alert_json.c
root committedApr 18, 2013 Configuration menu - View commit details
-
Copy full SHA for 5d886ca - Browse repository at this point
Copy the full SHA 5d886caView commit details -
Delayed KafkaLog's handler init in daemon mode (Need to do because a
fork() in that mode). modified: src/output-plugins/spo_alert_json.c modified: src/sfutil/sf_kafka.c modified: src/sfutil/sf_kafka.h
root committedApr 18, 2013 Configuration menu - View commit details
-
Copy full SHA for 6d76240 - Browse repository at this point
Copy the full SHA 6d76240View commit details -
Increased spo_alert_json LOG_BUFFER; Kafka split messages with just 4K
modified: src/output-plugins/spo_alert_json.c
root committedApr 18, 2013 Configuration menu - View commit details
-
Copy full SHA for 615879c - Browse repository at this point
Copy the full SHA 615879cView commit details
Commits on May 3, 2013
-
Changed the way sf_kafka use the buffer. Now it allocate a new one an…
…d let librdkafka free it. deleted: src/output-plugins/kafka/librdkafka.a deleted: src/output-plugins/kafka/rdkafka.h modified: src/sfutil/sf_kafka.c modified: src/sfutil/sf_kafka.h
root committedMay 3, 2013 Configuration menu - View commit details
-
Copy full SHA for 43a2c43 - Browse repository at this point
Copy the full SHA 43a2c43View commit details -
FIX: When sending alerts, sometimes proto was not set, so the json alert
contained a blank space in arguments, surrounded by commas (", ,"). Now, if the alert's proto is not valid, we don't send the comma. modified: src/output-plugins/spo_alert_json.c
root committedMay 3, 2013 Configuration menu - View commit details
-
Copy full SHA for b1f4acc - Browse repository at this point
Copy the full SHA b1f4accView commit details
Commits on Jul 3, 2013
-
Bumped: version to 2-1.13-BETA
Bumped: build to 325 Add: Full support for sid-msg v2 format which enchanced by the following fields: gid,revision,classification,priority for each entry which allow pre-population of signature metadata by barnyard2 if database output is used. Add: Signature Suppression support at the spooler level using configuration directive. See doc/README.sig_suppress Add: Variable resolving/support in configuration file (generic variable. Add: hostname and interface to possible CSV field Feature requested by: Phil Daws Add: spo_database configuration keyword "disable_signature_reference_table" was added and reconnect_sleep_time, connection_limit defined in doc/README.database. Fixed: Added extra check when generating sig_reference cache. (Martin Olsson) Fixed: sid-msg.map and gen-msg.map double declaration issue (using command line and directive is now prohibited) [ will bail if both are used (-S and config sid_file OR -G and config gen_file.] Fixed: syslog_full in complete mode IP information (Fäbu Hufi) Fixed: database, could stop processing event when some ip options where null (John Naggets) Fixed: Removed some database messages and move them to debug message if the propre debug flag is used.
Configuration menu - View commit details
-
Copy full SHA for de53c97 - Browse repository at this point
Copy the full SHA de53c97View commit details -
Last minute commit for a long waited needed feature and some little fix.
Add: Support for proper signal handling. Add: README info for google mailing lists. Fixed: Compile issue when debug was enabled (missing , in some DEBUG_WRAP code. Fixed: Changed a few places where the snort literal was used instead of barnyard2 and this could confuse some first time barnyard2 users. Fixed: RPM spec file to point to good version (when needed) Bumped: Build to 326 --github specific Fixes firnsy#81 Fixes firnsy#73 Fixes firnsy#75 Close firnsy#82 Close firnsy#83 Close firnsy#80 Close firnsy#79 Close firnsy#78 Close firnsy#27 --github specific
Configuration menu - View commit details
-
Copy full SHA for 5796f03 - Browse repository at this point
Copy the full SHA 5796f03View commit details -
Configuration menu - View commit details
-
Copy full SHA for 99c8188 - Browse repository at this point
Copy the full SHA 99c8188View commit details -
Configuration menu - View commit details
-
Copy full SHA for bcbd6b0 - Browse repository at this point
Copy the full SHA bcbd6b0View commit details -
Configuration menu - View commit details
-
Copy full SHA for 33f49f8 - Browse repository at this point
Copy the full SHA 33f49f8View commit details -
Configuration menu - View commit details
-
Copy full SHA for b0ccd22 - Browse repository at this point
Copy the full SHA b0ccd22View commit details -
Configuration menu - View commit details
-
Copy full SHA for 317f4be - Browse repository at this point
Copy the full SHA 317f4beView commit details -
Configuration menu - View commit details
-
Copy full SHA for d856c41 - Browse repository at this point
Copy the full SHA d856c41View commit details -
Configuration menu - View commit details
-
Copy full SHA for 5fefbe0 - Browse repository at this point
Copy the full SHA 5fefbe0View commit details -
Added src_name, src_str, dst_name and dst_str to json fields, based on
/opt/rb/etc/{hosts,networks} files modified: output-plugins/spo_alert_json.c
Configuration menu - View commit details
-
Copy full SHA for 1126d59 - Browse repository at this point
Copy the full SHA 1126d59View commit details -
Added network identifications in source and destination ip
modified: output-plugins/spo_alert_json.c
Configuration menu - View commit details
-
Copy full SHA for f048121 - Browse repository at this point
Copy the full SHA f048121View commit details -
Added geoIP support using maxmind GeoIP
modified: Makefile.am modified: output-plugins/spo_alert_json.c
Configuration menu - View commit details
-
Copy full SHA for 0896ef8 - Browse repository at this point
Copy the full SHA 0896ef8View commit details -
modified: src/sfutil/sf_kafka.c
Configuration menu - View commit details
-
Copy full SHA for dd159ed - Browse repository at this point
Copy the full SHA dd159edView commit details -
Fixed some possible memory leaks and enabled --enable-geo-ip in
configure script modified: configure.in modified: src/output-plugins/spo_alert_json.c
Configuration menu - View commit details
-
Copy full SHA for 6072ae5 - Browse repository at this point
Copy the full SHA 6072ae5View commit details -
Configuration menu - View commit details
-
Copy full SHA for 974bef5 - Browse repository at this point
Copy the full SHA 974bef5View commit details -
Added to sf_kafka a maximum queue length value
modified: sfutil/sf_kafka.c
Configuration menu - View commit details
-
Copy full SHA for 72b1321 - Browse repository at this point
Copy the full SHA 72b1321View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7f1de11 - Browse repository at this point
Copy the full SHA 7f1de11View commit details -
Added json and geoIP libs conditional compile stuff in configure.in.
KafkaLog now have a TextLog to print to a file, and alert_json does not have to worry about send to kafka and to a textfile.
Configuration menu - View commit details
-
Copy full SHA for 4d2fbf3 - Browse repository at this point
Copy the full SHA 4d2fbf3View commit details -
Configuration menu - View commit details
-
Copy full SHA for 563bc89 - Browse repository at this point
Copy the full SHA 563bc89View commit details -
Configuration menu - View commit details
-
Copy full SHA for 0459902 - Browse repository at this point
Copy the full SHA 0459902View commit details -
Added priority and classification fields to alert_json plugin. Some f…
…ields will be always printed, too
Configuration menu - View commit details
-
Copy full SHA for ee5eca8 - Browse repository at this point
Copy the full SHA ee5eca8View commit details -
Configuration menu - View commit details
-
Copy full SHA for f4cb1c3 - Browse repository at this point
Copy the full SHA f4cb1c3View commit details -
Added sensor_id and sensor_name passed by params. We will send the co…
…untry code in s_ip and dest_ip too.
Configuration menu - View commit details
-
Copy full SHA for a80dd89 - Browse repository at this point
Copy the full SHA a80dd89View commit details -
Using sf_ip from sfutils module, what simplifies a bit the name resol…
…ution Managed a geoip NULL return when ip is not in the database.
Configuration menu - View commit details
-
Copy full SHA for c6f50a5 - Browse repository at this point
Copy the full SHA c6f50a5View commit details -
Configuration menu - View commit details
-
Copy full SHA for b03bb29 - Browse repository at this point
Copy the full SHA b03bb29View commit details
Commits on Jul 4, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 2b98f85 - Browse repository at this point
Copy the full SHA 2b98f85View commit details -
Configuration menu - View commit details
-
Copy full SHA for dfea910 - Browse repository at this point
Copy the full SHA dfea910View commit details
Commits on Jul 8, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 67a8c03 - Browse repository at this point
Copy the full SHA 67a8c03View commit details
Commits on Jul 10, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 44ad609 - Browse repository at this point
Copy the full SHA 44ad609View commit details -
Configuration menu - View commit details
-
Copy full SHA for 5a8741d - Browse repository at this point
Copy the full SHA 5a8741dView commit details -
Configuration menu - View commit details
-
Copy full SHA for 05fcdc2 - Browse repository at this point
Copy the full SHA 05fcdc2View commit details -
Configuration menu - View commit details
-
Copy full SHA for aacf0d9 - Browse repository at this point
Copy the full SHA aacf0d9View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7e2eda9 - Browse repository at this point
Copy the full SHA 7e2eda9View commit details -
Configuration menu - View commit details
-
Copy full SHA for cb52266 - Browse repository at this point
Copy the full SHA cb52266View commit details -
Configuration menu - View commit details
-
Copy full SHA for dba7696 - Browse repository at this point
Copy the full SHA dba7696View commit details -
Configuration menu - View commit details
-
Copy full SHA for 8ac1090 - Browse repository at this point
Copy the full SHA 8ac1090View commit details
Commits on Jul 11, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 3f2a03a - Browse repository at this point
Copy the full SHA 3f2a03aView commit details
Commits on Jul 12, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 99adef9 - Browse repository at this point
Copy the full SHA 99adef9View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9a808be - Browse repository at this point
Copy the full SHA 9a808beView commit details -
Configuration menu - View commit details
-
Copy full SHA for 3e97959 - Browse repository at this point
Copy the full SHA 3e97959View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9758863 - Browse repository at this point
Copy the full SHA 9758863View commit details
Commits on Jul 13, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 38f3cac - Browse repository at this point
Copy the full SHA 38f3cacView commit details
Commits on Jul 15, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 262c850 - Browse repository at this point
Copy the full SHA 262c850View commit details -
Configuration menu - View commit details
-
Copy full SHA for f8519e9 - Browse repository at this point
Copy the full SHA f8519e9View commit details
Commits on Jul 16, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 8fd7109 - Browse repository at this point
Copy the full SHA 8fd7109View commit details
Commits on Jul 17, 2013
-
Deleted all slow KafkaLog_Print and changed to KafkaLog_Puts. Added a…
… _itoa function to convert number to string. Template default values changed from void* to char*
Configuration menu - View commit details
-
Copy full SHA for fcdbe8f - Browse repository at this point
Copy the full SHA fcdbe8fView commit details -
changed a snprintf to a strcat in KafkaLog_Write: performance
KafkaLog->maxBuf renamed to kafkaLog->bufLen and start_bufLen, more descriptive ones
Configuration menu - View commit details
-
Copy full SHA for de16a9d - Browse repository at this point
Copy the full SHA de16a9dView commit details -
Configuration menu - View commit details
-
Copy full SHA for c7477a5 - Browse repository at this point
Copy the full SHA c7477a5View commit details
Commits on Jul 25, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 529e965 - Browse repository at this point
Copy the full SHA 529e965View commit details
Commits on Jul 30, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 47af71b - Browse repository at this point
Copy the full SHA 47af71bView commit details
Commits on Aug 1, 2013
-
Changed configure.in so it can import rdkafka from any location. Now you
can specify kafka location using --with-kafka-* params configure params.
Configuration menu - View commit details
-
Copy full SHA for b346855 - Browse repository at this point
Copy the full SHA b346855View commit details -
Added rb_pointers.h header to have specific commands to check pointer…
…s. Added type,domain,domain_id template parameters too.
Configuration menu - View commit details
-
Copy full SHA for 1971669 - Browse repository at this point
Copy the full SHA 1971669View commit details -
Configuration menu - View commit details
-
Copy full SHA for f7eff47 - Browse repository at this point
Copy the full SHA f7eff47View commit details
Commits on Aug 2, 2013
-
Sending action of message (not fully supported). Some numbers sended …
…in hex format => json not supported.
Configuration menu - View commit details
-
Copy full SHA for 70ae7b8 - Browse repository at this point
Copy the full SHA 70ae7b8View commit details -
IPv4 sended in wrong format. Deleted a warning. fwsam did not compile…
… if ipv6 enabled.
Configuration menu - View commit details
-
Copy full SHA for de518d2 - Browse repository at this point
Copy the full SHA de518d2View commit details -
Configuration menu - View commit details
-
Copy full SHA for 2da769a - Browse repository at this point
Copy the full SHA 2da769aView commit details -
Configuration menu - View commit details
-
Copy full SHA for 038d63a - Browse repository at this point
Copy the full SHA 038d63aView commit details
Commits on Aug 7, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 55859fc - Browse repository at this point
Copy the full SHA 55859fcView commit details
Commits on Aug 12, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 003086d - Browse repository at this point
Copy the full SHA 003086dView commit details
Commits on Aug 22, 2013
-
Configuration menu - View commit details
-
Copy full SHA for e11344d - Browse repository at this point
Copy the full SHA e11344dView commit details
Commits on Aug 23, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 0665f85 - Browse repository at this point
Copy the full SHA 0665f85View commit details -
Configuration menu - View commit details
-
Copy full SHA for 9bc12e3 - Browse repository at this point
Copy the full SHA 9bc12e3View commit details
Commits on Sep 16, 2013
-
Configuration menu - View commit details
-
Copy full SHA for a3a04f1 - Browse repository at this point
Copy the full SHA a3a04f1View commit details
Commits on Sep 24, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 37c67a5 - Browse repository at this point
Copy the full SHA 37c67a5View commit details
Commits on Oct 9, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 4d4b105 - Browse repository at this point
Copy the full SHA 4d4b105View commit details
Commits on Nov 5, 2013
-
Added group_id and group_name in the parameters. domain_id renamed to…
… domain_name, and domain->domain_id
Configuration menu - View commit details
-
Copy full SHA for 3300b02 - Browse repository at this point
Copy the full SHA 3300b02View commit details
Commits on Nov 19, 2013
-
IP packets length and ethernet packets length are now aggregated in g…
…roups. Priority_name added.
Configuration menu - View commit details
-
Copy full SHA for a50d5cc - Browse repository at this point
Copy the full SHA a50d5ccView commit details
Commits on Nov 21, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 8f6035a - Browse repository at this point
Copy the full SHA 8f6035aView commit details -
Configuration menu - View commit details
-
Copy full SHA for 0f2e165 - Browse repository at this point
Copy the full SHA 0f2e165View commit details
Commits on Nov 28, 2013
-
Configuration menu - View commit details
-
Copy full SHA for 770955c - Browse repository at this point
Copy the full SHA 770955cView commit details
Commits on Dec 5, 2013
-
Configuration menu - View commit details
-
Copy full SHA for d24420d - Browse repository at this point
Copy the full SHA d24420dView commit details -
Configuration menu - View commit details
-
Copy full SHA for 9bcd10b - Browse repository at this point
Copy the full SHA 9bcd10bView commit details
Commits on Dec 18, 2013
-
Configuration menu - View commit details
-
Copy full SHA for e823da9 - Browse repository at this point
Copy the full SHA e823da9View commit details
Commits on Dec 26, 2013
-
Configuration menu - View commit details
-
Copy full SHA for ab3c3da - Browse repository at this point
Copy the full SHA ab3c3daView commit details -
Configuration menu - View commit details
-
Copy full SHA for 5086948 - Browse repository at this point
Copy the full SHA 5086948View commit details
Commits on Jan 15, 2014
-
Configuration menu - View commit details
-
Copy full SHA for 4b33b2f - Browse repository at this point
Copy the full SHA 4b33b2fView commit details
Commits on Apr 30, 2014
-
Configuration menu - View commit details
-
Copy full SHA for 4fa91db - Browse repository at this point
Copy the full SHA 4fa91dbView commit details -
FIX: rb_kafka didn't compile if not --enable-rdkafka present (thanks …
…to Alberto for reporting)
Configuration menu - View commit details
-
Copy full SHA for a56f46c - Browse repository at this point
Copy the full SHA a56f46cView commit details
Commits on May 26, 2014
-
Configuration menu - View commit details
-
Copy full SHA for 56c8d63 - Browse repository at this point
Copy the full SHA 56c8d63View commit details
Commits on May 27, 2014
-
Configuration menu - View commit details
-
Copy full SHA for f272e43 - Browse repository at this point
Copy the full SHA f272e43View commit details -
Configuration menu - View commit details
-
Copy full SHA for ac57192 - Browse repository at this point
Copy the full SHA ac57192View commit details
Commits on Jul 11, 2014
-
Configuration menu - View commit details
-
Copy full SHA for 34376d1 - Browse repository at this point
Copy the full SHA 34376d1View commit details
Commits on Jul 14, 2014
-
Configuration menu - View commit details
-
Copy full SHA for e3baa9b - Browse repository at this point
Copy the full SHA e3baa9bView commit details -
Configuration menu - View commit details
-
Copy full SHA for 37a8067 - Browse repository at this point
Copy the full SHA 37a8067View commit details
Commits on Jul 15, 2014
-
Configuration menu - View commit details
-
Copy full SHA for 3ab793e - Browse repository at this point
Copy the full SHA 3ab793eView commit details
Commits on Jul 16, 2014
-
Configuration menu - View commit details
-
Copy full SHA for d653674 - Browse repository at this point
Copy the full SHA d653674View commit details
Commits on Jul 17, 2014
-
Barnyard cache is now freeing at the end, instead of start. This avoi…
…ds a lot of lonely packet events
Configuration menu - View commit details
-
Copy full SHA for 25f5f6f - Browse repository at this point
Copy the full SHA 25f5f6fView commit details -
Configuration menu - View commit details
-
Copy full SHA for 208ace4 - Browse repository at this point
Copy the full SHA 208ace4View commit details
Commits on Jul 18, 2014
-
Configuration menu - View commit details
-
Copy full SHA for a9de004 - Browse repository at this point
Copy the full SHA a9de004View commit details -
Configuration menu - View commit details
-
Copy full SHA for 7158760 - Browse repository at this point
Copy the full SHA 7158760View commit details
Commits on Jul 21, 2014
-
src and dst port now extracted from the event instead of the packet. …
…If cannot extract from event, then try to extract from packet.
Configuration menu - View commit details
-
Copy full SHA for 64f9cfd - Browse repository at this point
Copy the full SHA 64f9cfdView commit details -
Configuration menu - View commit details
-
Copy full SHA for 0f49c62 - Browse repository at this point
Copy the full SHA 0f49c62View commit details -
extract icmp code first from event that from packet. ICMP code & type…
… only printed if icmp protocolot event
Configuration menu - View commit details
-
Copy full SHA for 99fb126 - Browse repository at this point
Copy the full SHA 99fb126View commit details -
Configuration menu - View commit details
-
Copy full SHA for f00d29d - Browse repository at this point
Copy the full SHA f00d29dView commit details -
Configuration menu - View commit details
-
Copy full SHA for e103aac - Browse repository at this point
Copy the full SHA e103aacView commit details -
Configuration menu - View commit details
-
Copy full SHA for b0103b1 - Browse repository at this point
Copy the full SHA b0103b1View commit details -
Configuration menu - View commit details
-
Copy full SHA for c3c02f0 - Browse repository at this point
Copy the full SHA c3c02f0View commit details -
Configuration menu - View commit details
-
Copy full SHA for 03555b0 - Browse repository at this point
Copy the full SHA 03555b0View commit details
Commits on Aug 28, 2014
-
Configuration menu - View commit details
-
Copy full SHA for 7601011 - Browse repository at this point
Copy the full SHA 7601011View commit details -
Configuration menu - View commit details
-
Copy full SHA for 6d2eb21 - Browse repository at this point
Copy the full SHA 6d2eb21View commit details -
Configuration menu - View commit details
-
Copy full SHA for 5fa044b - Browse repository at this point
Copy the full SHA 5fa044bView commit details
Commits on Aug 29, 2014
-
Configuration menu - View commit details
-
Copy full SHA for 9f5c7ad - Browse repository at this point
Copy the full SHA 9f5c7adView commit details -
Configuration menu - View commit details
-
Copy full SHA for 078102a - Browse repository at this point
Copy the full SHA 078102aView commit details -
Configuration menu - View commit details
-
Copy full SHA for 485110f - Browse repository at this point
Copy the full SHA 485110fView commit details -
Configuration menu - View commit details
-
Copy full SHA for 7099fe5 - Browse repository at this point
Copy the full SHA 7099fe5View commit details
Commits on Sep 1, 2014
-
Configuration menu - View commit details
-
Copy full SHA for b46067c - Browse repository at this point
Copy the full SHA b46067cView commit details
Commits on Sep 2, 2014
-
Configuration menu - View commit details
-
Copy full SHA for b3f9d72 - Browse repository at this point
Copy the full SHA b3f9d72View commit details
Commits on Oct 30, 2014
-
Configuration menu - View commit details
-
Copy full SHA for a38c808 - Browse repository at this point
Copy the full SHA a38c808View commit details -
Configuration menu - View commit details
-
Copy full SHA for 6099b36 - Browse repository at this point
Copy the full SHA 6099b36View commit details
Commits on Mar 26, 2015
-
Included Extra Data counts in Records
Pablo Cantos committedMar 26, 2015 Configuration menu - View commit details
-
Copy full SHA for e0ea441 - Browse repository at this point
Copy the full SHA e0ea441View commit details
Commits on Mar 30, 2015
-
Preparing spo_alert_json.c, plugbase.c and plugbase.h. Perhaps we wil…
…l have to roll back to undo these changes.
Pablo Cantos committedMar 30, 2015 Configuration menu - View commit details
-
Copy full SHA for 13cbf23 - Browse repository at this point
Copy the full SHA 13cbf23View commit details
Commits on Mar 31, 2015
-
Flush cached event after TIME_ALARM seconds: Setting Alarm
Pablo Cantos committedMar 31, 2015 Configuration menu - View commit details
-
Copy full SHA for 411cc8f - Browse repository at this point
Copy the full SHA 411cc8fView commit details
Commits on Apr 7, 2015
-
Changing the way spoolerProcessRecord works and including Extra Data …
…in EventRecordNode->data
Pablo Cantos committedApr 7, 2015 Configuration menu - View commit details
-
Copy full SHA for fe432e5 - Browse repository at this point
Copy the full SHA fe432e5View commit details -
Fire remained events before closing spooler when EOF is reached
Pablo Cantos committedApr 7, 2015 Configuration menu - View commit details
-
Copy full SHA for 8a01fd9 - Browse repository at this point
Copy the full SHA 8a01fd9View commit details
Commits on Apr 10, 2015
-
rd_unified2.c modified: fixing macro and actionOfEvent
Pablo Cantos committedApr 10, 2015 Configuration menu - View commit details
-
Copy full SHA for e17f878 - Browse repository at this point
Copy the full SHA e17f878View commit details -
Merge branch 'master' into ExtraData
Pablo Cantos committedApr 10, 2015 Configuration menu - View commit details
-
Copy full SHA for 2e91674 - Browse repository at this point
Copy the full SHA 2e91674View commit details -
spo_alert_json.c modified: getting events from spooler and producing …
…kafka messages with extra data
Pablo Cantos committedApr 10, 2015 Configuration menu - View commit details
-
Copy full SHA for 1215ad4 - Browse repository at this point
Copy the full SHA 1215ad4View commit details -
Configuration menu - View commit details
-
Copy full SHA for fc3035b - Browse repository at this point
Copy the full SHA fc3035bView commit details -
Configuration menu - View commit details
-
Copy full SHA for e25213d - Browse repository at this point
Copy the full SHA e25213dView commit details
Commits on Apr 13, 2015
-
Merge branch 'master' into ExtraData
Pablo Cantos committedApr 13, 2015 Configuration menu - View commit details
-
Copy full SHA for fd044e7 - Browse repository at this point
Copy the full SHA fd044e7View commit details
Commits on Apr 14, 2015
-
Pablo Cantos committed
Apr 14, 2015 Configuration menu - View commit details
-
Copy full SHA for a1b3487 - Browse repository at this point
Copy the full SHA a1b3487View commit details -
Fixing/readjusting some pieces of code
Pablo Cantos committedApr 14, 2015 Configuration menu - View commit details
-
Copy full SHA for 10a40c1 - Browse repository at this point
Copy the full SHA 10a40c1View commit details -
Comment added to explain payload not matching
Pablo Cantos committedApr 14, 2015 Configuration menu - View commit details
-
Copy full SHA for f45af1e - Browse repository at this point
Copy the full SHA f45af1eView commit details -
Merge branch 'master' into ExtraData
Pablo Cantos committedApr 14, 2015 Configuration menu - View commit details
-
Copy full SHA for 6d2b8b2 - Browse repository at this point
Copy the full SHA 6d2b8b2View commit details -
Pablo Cantos committed
Apr 14, 2015 Configuration menu - View commit details
-
Copy full SHA for 57cf6a7 - Browse repository at this point
Copy the full SHA 57cf6a7View commit details -
Pablo Cantos committed
Apr 14, 2015 Configuration menu - View commit details
-
Copy full SHA for 2c06993 - Browse repository at this point
Copy the full SHA 2c06993View commit details
Commits on Apr 15, 2015
-
Including macro RB_EXTRADATA in configure. Short change in spoolerExt…
…raDataCacheClean().
Pablo Cantos committedApr 15, 2015 Configuration menu - View commit details
-
Copy full SHA for c5a3d45 - Browse repository at this point
Copy the full SHA c5a3d45View commit details
Commits on Apr 17, 2015
-
Changing the way DEFAULT_JSON is defined. Including code to write URI…
… and hostname as ExtraData.
Pablo Cantos committedApr 17, 2015 Configuration menu - View commit details
-
Copy full SHA for 185858f - Browse repository at this point
Copy the full SHA 185858fView commit details
Commits on Apr 28, 2015
-
changed file_sha256 by sha256 in spo_alert_json.c
Pablo Cantos committedApr 28, 2015 Configuration menu - View commit details
-
Copy full SHA for e0177f3 - Browse repository at this point
Copy the full SHA e0177f3View commit details
Commits on May 18, 2015
-
Configuration menu - View commit details
-
Copy full SHA for 9285734 - Browse repository at this point
Copy the full SHA 9285734View commit details -
Added enrich_with output json parameter. Deleted a few deprecated par…
…ameters because they can be included in enruch_with
Configuration menu - View commit details
-
Copy full SHA for e512180 - Browse repository at this point
Copy the full SHA e512180View commit details -
Configuration menu - View commit details
-
Copy full SHA for 21edda4 - Browse repository at this point
Copy the full SHA 21edda4View commit details -
Configuration menu - View commit details
-
Copy full SHA for 2238c7e - Browse repository at this point
Copy the full SHA 2238c7eView commit details
Commits on May 22, 2015
-
Pablo Cantos committed
May 22, 2015 Configuration menu - View commit details
-
Copy full SHA for 7ce4263 - Browse repository at this point
Copy the full SHA 7ce4263View commit details -
Pablo Cantos committed
May 22, 2015 Configuration menu - View commit details
-
Copy full SHA for 2baa664 - Browse repository at this point
Copy the full SHA 2baa664View commit details
Commits on Jul 1, 2015
-
Configuration menu - View commit details
-
Copy full SHA for 09c1d96 - Browse repository at this point
Copy the full SHA 09c1d96View commit details
Commits on Jul 10, 2015
-
SMTP ExtraData fields included
Pablo Cantos committedJul 10, 2015 Configuration menu - View commit details
-
Copy full SHA for 609383d - Browse repository at this point
Copy the full SHA 609383dView commit details
Commits on Jul 13, 2015
-
FIX: Last event discarded when opening a new snort.log file (redmine …
…issue #4834)
Pablo Cantos committedJul 13, 2015 Configuration menu - View commit details
-
Copy full SHA for f6ed494 - Browse repository at this point
Copy the full SHA f6ed494View commit details
Commits on Sep 29, 2015
-
Configuration menu - View commit details
-
Copy full SHA for 8271632 - Browse repository at this point
Copy the full SHA 8271632View commit details
Commits on Sep 30, 2015
-
Configuration menu - View commit details
-
Copy full SHA for d6548f6 - Browse repository at this point
Copy the full SHA d6548f6View commit details -
Configuration menu - View commit details
-
Copy full SHA for c550318 - Browse repository at this point
Copy the full SHA c550318View commit details
Commits on Oct 1, 2015
-
Configuration menu - View commit details
-
Copy full SHA for 5ab2438 - Browse repository at this point
Copy the full SHA 5ab2438View commit details -
Configuration menu - View commit details
-
Copy full SHA for d1de5ad - Browse repository at this point
Copy the full SHA d1de5adView commit details
Commits on Oct 2, 2015
-
Configuration menu - View commit details
-
Copy full SHA for c342656 - Browse repository at this point
Copy the full SHA c342656View commit details -
Configuration menu - View commit details
-
Copy full SHA for 4098604 - Browse repository at this point
Copy the full SHA 4098604View commit details -
Configuration menu - View commit details
-
Copy full SHA for c79b801 - Browse repository at this point
Copy the full SHA c79b801View commit details
Commits on Oct 13, 2015
-
Configuration menu - View commit details
-
Copy full SHA for 9827bd8 - Browse repository at this point
Copy the full SHA 9827bd8View commit details
Commits on Oct 14, 2015
-
Configuration menu - View commit details
-
Copy full SHA for d6edcea - Browse repository at this point
Copy the full SHA d6edceaView commit details
Commits on Dec 18, 2015
-
Configuration menu - View commit details
-
Copy full SHA for 284cdb8 - Browse repository at this point
Copy the full SHA 284cdb8View commit details
Commits on Dec 21, 2015
-
Configuration menu - View commit details
-
Copy full SHA for 81801dd - Browse repository at this point
Copy the full SHA 81801ddView commit details -
Configuration menu - View commit details
-
Copy full SHA for fd503de - Browse repository at this point
Copy the full SHA fd503deView commit details -
Configuration menu - View commit details
-
Copy full SHA for 44ade9c - Browse repository at this point
Copy the full SHA 44ade9cView commit details
Commits on Jan 13, 2016
-
Configuration menu - View commit details
-
Copy full SHA for c4bea65 - Browse repository at this point
Copy the full SHA c4bea65View commit details
Commits on Jan 14, 2016
-
Configuration menu - View commit details
-
Copy full SHA for 63ef7a7 - Browse repository at this point
Copy the full SHA 63ef7a7View commit details -
Configuration menu - View commit details
-
Copy full SHA for d19a0ee - Browse repository at this point
Copy the full SHA d19a0eeView commit details
Commits on Jan 28, 2016
-
Configuration menu - View commit details
-
Copy full SHA for 55eb651 - Browse repository at this point
Copy the full SHA 55eb651View commit details -
Configuration menu - View commit details
-
Copy full SHA for 852945d - Browse repository at this point
Copy the full SHA 852945dView commit details
Commits on Feb 1, 2016
-
Configuration menu - View commit details
-
Copy full SHA for 75da520 - Browse repository at this point
Copy the full SHA 75da520View commit details -
Configuration menu - View commit details
-
Copy full SHA for ab605f7 - Browse repository at this point
Copy the full SHA ab605f7View commit details -
Configuration menu - View commit details
-
Copy full SHA for ad18a9d - Browse repository at this point
Copy the full SHA ad18a9dView commit details -
Configuration menu - View commit details
-
Copy full SHA for 0b1f424 - Browse repository at this point
Copy the full SHA 0b1f424View commit details -
Configuration menu - View commit details
-
Copy full SHA for eb3f943 - Browse repository at this point
Copy the full SHA eb3f943View commit details -
Merge pull request #4 from Bigomby/Feature/Managing_ExtraData_fields
Feature/managing extra data fields
Configuration menu - View commit details
-
Copy full SHA for 9bb391b - Browse repository at this point
Copy the full SHA 9bb391bView commit details -
Configuration menu - View commit details
-
Copy full SHA for 8a6997b - Browse repository at this point
Copy the full SHA 8a6997bView commit details
Commits on Feb 4, 2016
-
1417 ==1438== 1418 ==1438== More than 100 errors detected. Subsequent errors 1419 ==1438== will still be recorded, but in less detail than before. 1420 ==1438== Invalid free() / delete / delete[] / realloc() 1421 ==1438== at 0x4C27430: free (vg_replace_malloc.c:446) 1422 ==1438== by 0x4202DC: AlertJSONCleanup (spo_alert_json.c:1018) 1423 ==1438== by 0x403EF2: Barnyard2Cleanup (barnyard2.c:1122) 1424 ==1438== by 0x40428C: SignalCheck (barnyard2.c:1405) 1425 ==1438== by 0x405E1F: Barnyard2Main (barnyard2.c:395) 1426 ==1438== by 0x6185D5C: (below main) (in /lib64/libc-2.12.so) 1427 ==1438== Address 0x79cc8e0 is 0 bytes inside a block of size 24 free'd 1428 ==1438== at 0x4C27430: free (vg_replace_malloc.c:446) 1429 ==1438== by 0x4202DC: AlertJSONCleanup (spo_alert_json.c:1018) 1430 ==1438== by 0x403EF2: Barnyard2Cleanup (barnyard2.c:1122) 1431 ==1438== by 0x40428C: SignalCheck (barnyard2.c:1405) 1432 ==1438== by 0x405E1F: Barnyard2Main (barnyard2.c:395) 1433 ==1438== by 0x6185D5C: (below main) (in /lib64/libc-2.12.so)
Ana Rey committedFeb 4, 2016 Configuration menu - View commit details
-
Copy full SHA for 02140d8 - Browse repository at this point
Copy the full SHA 02140d8View commit details -
Merge pull request #5 from anarey/feature/extra_data_bug
Fixed invalid free memory
Configuration menu - View commit details
-
Copy full SHA for 5357d16 - Browse repository at this point
Copy the full SHA 5357d16View commit details -
Bug: leak memory. Do not free the eth_vendors_db elemnt
==7242== 1 bytes in 1 blocks are still reachable in loss record 1 of 33 ==7242== at 0x4C27A2E: malloc (vg_replace_malloc.c:270) ==7242== by 0x61E7EC1: strdup (in /lib64/libc-2.12.so) ==7242== by 0x5253D3D: rd_memctx_init (in /opt/rb/lib/librd.so) ==7242== by 0x5F65C9B: rb_new_mac_vendor_db (in /opt/rb/lib/librb_mac_vendors.so.0) ==7242== by 0x421EA7: AlertJSONParseArgs (spo_alert_json.c:728) ==7242== by 0x42252A: AlertJSONInit (spo_alert_json.c:360) ==7242== by 0x413969: ConfigureOutputPlugins (parser.c:609) ==7242== by 0x405654: Barnyard2Init (barnyard2.c:2092) ==7242== by 0x405DCA: Barnyard2Main (barnyard2.c:325) ==7242== by 0x6185D5C: (below main) (in /lib64/libc-2.12.so)
Ana Rey committedFeb 4, 2016 Configuration menu - View commit details
-
Copy full SHA for 4469f7a - Browse repository at this point
Copy the full SHA 4469f7aView commit details
Commits on Feb 15, 2016
-
Configuration menu - View commit details
-
Copy full SHA for cb2f2bd - Browse repository at this point
Copy the full SHA cb2f2bdView commit details -
Merge pull request #7 from anarey/feature/extra_data_bug2
Freeing memory at the end of barnyard2 execution
Configuration menu - View commit details
-
Copy full SHA for 8f0d510 - Browse repository at this point
Copy the full SHA 8f0d510View commit details -
extradata: deleted "<" and ">" caracteres in email_sender element
Exmaple: "email_sender": "ejimenez@redborder.net", Old format: "email_sender": "<ejimenez@redborder.net>",
Configuration menu - View commit details
-
Copy full SHA for 76bffce - Browse repository at this point
Copy the full SHA 76bffceView commit details -
extradata: email_destination in an array
Example: "email_destinations":"[\"rcpt1@redborder.net\",\"rcpt2@redborder.net\",\"rcpt3@redborder.net\"]" "email_destinations":"[\"malware@redborder.net>\"]"
Configuration menu - View commit details
-
Copy full SHA for 4a1ec75 - Browse repository at this point
Copy the full SHA 4a1ec75View commit details
Commits on Feb 16, 2016
-
Merge pull request #8 from anarey/feature/email-destinations
Feature/email destinations
Configuration menu - View commit details
-
Copy full SHA for 150d5fb - Browse repository at this point
Copy the full SHA 150d5fbView commit details -
Configuration menu - View commit details
-
Copy full SHA for 3fe7c2e - Browse repository at this point
Copy the full SHA 3fe7c2eView commit details -
Configuration menu - View commit details
-
Copy full SHA for abd4f8e - Browse repository at this point
Copy the full SHA abd4f8eView commit details -
Configuration menu - View commit details
-
Copy full SHA for a859ac8 - Browse repository at this point
Copy the full SHA a859ac8View commit details
Commits on Feb 22, 2016
-
Fix in Alarm Control for spoolerFireLastEvent()
Pablo Cantos committedFeb 22, 2016 Configuration menu - View commit details
-
Copy full SHA for 888586a - Browse repository at this point
Copy the full SHA 888586aView commit details -
Added spoolerPrint*() functions for debug purposes
Pablo Cantos committedFeb 22, 2016 Configuration menu - View commit details
-
Copy full SHA for 05ac8f1 - Browse repository at this point
Copy the full SHA 05ac8f1View commit details -
Protection added when reading from spooler
Pablo Cantos committedFeb 22, 2016 Configuration menu - View commit details
-
Copy full SHA for 9f5a4b3 - Browse repository at this point
Copy the full SHA 9f5a4b3View commit details
Commits on Feb 23, 2016
-
Merge branch 'Feature/Managing_ExtraData_fields' of github.com:redBor…
…der/barnyard2 into Feature/Managing_ExtraData_fields
Pablo Cantos committedFeb 23, 2016 Configuration menu - View commit details
-
Copy full SHA for 615324e - Browse repository at this point
Copy the full SHA 615324eView commit details -
Added spoolerPrint*Packet() functions for debug purposes
Pablo Cantos committedFeb 23, 2016 Configuration menu - View commit details
-
Copy full SHA for bc0e9a7 - Browse repository at this point
Copy the full SHA bc0e9a7View commit details -
Pablo Cantos committed
Feb 23, 2016 Configuration menu - View commit details
-
Copy full SHA for 40d8d26 - Browse repository at this point
Copy the full SHA 40d8d26View commit details
Commits on Mar 10, 2016
-
Configuration menu - View commit details
-
Copy full SHA for f23a075 - Browse repository at this point
Copy the full SHA f23a075View commit details -
Configuration menu - View commit details
-
Copy full SHA for d6fb823 - Browse repository at this point
Copy the full SHA d6fb823View commit details
Commits on Mar 15, 2016
-
Merge pull request #9 from Bigomby/Feature/Managing_ExtraData_fields
Added more default options
Configuration menu - View commit details
-
Copy full SHA for f327df1 - Browse repository at this point
Copy the full SHA f327df1View commit details -
Configuration menu - View commit details
-
Copy full SHA for 1d0f2e5 - Browse repository at this point
Copy the full SHA 1d0f2e5View commit details
Commits on Apr 27, 2016
-
Configuration menu - View commit details
-
Copy full SHA for 4e9c18f - Browse repository at this point
Copy the full SHA 4e9c18fView commit details -
Use printbuf_memappend_escaped in EVENT_INFO_FILE_NAME
Before of this, names with characters '\', '"' or control ones (<U+0020) in it's name would be printed as invalid JSON. With this escape function. With this escape function, the output will be a valid JSON.
Configuration menu - View commit details
-
Copy full SHA for 12f2a9a - Browse repository at this point
Copy the full SHA 12f2a9aView commit details
Commits on Apr 29, 2022
-
David Vanhoucke committed
Apr 29, 2022 Configuration menu - View commit details
-
Copy full SHA for c1cddd9 - Browse repository at this point
Copy the full SHA c1cddd9View commit details
Commits on May 11, 2022
-
Configuration menu - View commit details
-
Copy full SHA for 705de4f - Browse repository at this point
Copy the full SHA 705de4fView commit details
Commits on Nov 6, 2023
-
Configuration menu - View commit details
-
Copy full SHA for ef6ea9a - Browse repository at this point
Copy the full SHA ef6ea9aView commit details -
Configuration menu - View commit details
-
Copy full SHA for 64470a9 - Browse repository at this point
Copy the full SHA 64470a9View commit details -
Configuration menu - View commit details
-
Copy full SHA for 181ff00 - Browse repository at this point
Copy the full SHA 181ff00View commit details
Commits on Nov 8, 2023
-
Merge pull request #14 from redBorder/Feature/Managing_ExtraData_fields
Feature/managing extra data fields
Configuration menu - View commit details
-
Copy full SHA for d104676 - Browse repository at this point
Copy the full SHA d104676View commit details -
Configuration menu - View commit details
-
Copy full SHA for 06f8575 - Browse repository at this point
Copy the full SHA 06f8575View commit details
Commits on Apr 2, 2024
-
Configuration menu - View commit details
-
Copy full SHA for bd81df0 - Browse repository at this point
Copy the full SHA bd81df0View commit details
Commits on Apr 11, 2024
-
Configuration menu - View commit details
-
Copy full SHA for 0b4ea63 - Browse repository at this point
Copy the full SHA 0b4ea63View commit details -
Configuration menu - View commit details
-
Copy full SHA for 294aa24 - Browse repository at this point
Copy the full SHA 294aa24View commit details -
Merge pull request #16 from redBorder/improvement/#16872_rpm_package_…
…mock update process rpm creation
Configuration menu - View commit details
-
Copy full SHA for c639a2b - Browse repository at this point
Copy the full SHA c639a2bView commit details