Go to the documentation of this file.
54 #define LOG_EMAIL_DEFAULT 0
55 #define LOG_EMAIL_EXTENDED (1<<0)
56 #define LOG_EMAIL_ARRAY (1<<1)
57 #define LOG_EMAIL_COMMA (1<<2)
58 #define LOG_EMAIL_BODY_MD5 (1<<3)
59 #define LOG_EMAIL_SUBJECT_MD5 (1<<4)
85 static void EveEmailLogJSONMd5(
93 SCMimeSmtpLogSubjectMd5(js, entity);
101 SCMimeSmtpLogBodyMd5(js, entity);
105 static void EveEmailLogJSONCustom(
110 if (entity == NULL) {
115 if (((email_ctx->
fields & (1ULL<<
f)) != 0)
120 SCMimeSmtpLogFieldArray(
123 SCMimeSmtpLogFieldComma(
126 SCMimeSmtpLogFieldString(
136 static bool EveEmailLogJsonData(
140 MimeStateSMTP *mime_state;
147 if (smtp_state == NULL) {
148 SCLogDebug(
"no smtp state, so no request logging");
153 SCLogDebug(
"lets go mime_state %p", mime_state);
159 if ((mime_state != NULL)) {
160 SCMimeSmtpLogData(sjs, mime_state);
169 void *state,
void *vtx, uint64_t tx_id)
173 SCJsonBuilderMark mark = { 0, 0, 0 };
175 SCJbGetMark(js, &mark);
176 SCJbOpenObject(js,
"email");
177 if (!EveEmailLogJsonData(
f, state, vtx, tx_id, js)) {
178 SCJbRestoreMark(js, &mark);
183 EveEmailLogJSONCustom(email_ctx, js, tx);
186 EveEmailLogJSONMd5(email_ctx, js, tx);
199 return EveEmailLogJsonData(
f, smtp_state, tx, tx_id, js);
211 if (extended != NULL) {
226 email_ctx->
fields |= (1ULL <<
f);
234 email_ctx->
flags = 0;
239 if (strcmp(
"body", field->
val) == 0) {
240 SCLogInfo(
"Going to log the md5 sum of email body");
243 if (strcmp(
"subject", field->
val) == 0) {
244 SCLogInfo(
"Going to log the md5 sum of email subject");
struct SCJsonBuilder SCJsonBuilder
int SCConfValIsTrue(const char *val)
Check if a value is true.
#define LOG_EMAIL_EXTENDED
struct HtpBodyChunk_ * next
AppProto SCFlowGetAppProtocol(const Flow *f)
#define TAILQ_FOREACH(var, head, field)
TmEcode EveEmailLogJson(JsonEmailLogThread *aft, SCJsonBuilder *js, const Packet *p, Flow *f, void *state, void *vtx, uint64_t tx_id)
const char * SCConfNodeLookupChildValue(const SCConfNode *node, const char *name)
Lookup the value of a child configuration node by name.
struct @140 email_fields[]
#define SCLogInfo(...)
Macro used to log INFORMATIONAL messages.
void * AppLayerParserGetTx(uint8_t ipproto, AppProto alproto, void *alstate, uint64_t tx_id)
#define LOG_EMAIL_DEFAULT
SCConfNode * SCConfNodeLookupChild(const SCConfNode *node, const char *name)
Lookup a child configuration node by name.
bool EveEmailAddMetadata(const Flow *f, uint64_t tx_id, SCJsonBuilder *js)
const char * config_field
#define LOG_EMAIL_SUBJECT_MD5
void OutputEmailInitConf(SCConfNode *conf, OutputJsonEmailCtx *email_ctx)
OutputJsonEmailCtx * emaillog_ctx
#define LOG_EMAIL_BODY_MD5
MimeStateSMTP * mime_state