Go to the documentation of this file.
57 char srcip[46] = {0}, dstip[46] = {0};
71 PrintInet(AF_INET, (
const void *)&(
f->
src.addr_data32[0]), srcip,
sizeof(srcip));
72 PrintInet(AF_INET, (
const void *)&(
f->
dst.addr_data32[0]), dstip,
sizeof(dstip));
83 PrintInet(AF_INET, (
const void *)&(
f->
dst.addr_data32[0]), srcip,
sizeof(srcip));
84 PrintInet(AF_INET, (
const void *)&(
f->
src.addr_data32[0]), dstip,
sizeof(dstip));
96 SCJbSetString(jb,
"timestamp", timebuf);
103 json_object_set_new(js,
"sensor_id", json_integer(sensor_id));
109 SCJbSetString(jb,
"in_iface", dev->
dev);
116 SCJbOpenArray(jb,
"vlan");
128 SCJbSetString(jb,
"src_ip", srcip);
135 SCJbSetUint(jb,
"src_port", sp);
138 SCJbSetString(jb,
"dest_ip", dstip);
145 SCJbSetUint(jb,
"dest_port", dp);
151 SCJbSetUint(jb,
"ip_v", 4);
153 SCJbSetUint(jb,
"ip_v", 6);
161 SCJbSetString(jb,
"proto",
proto);
167 SCJbSetUint(jb,
"icmp_type",
f->
icmp_s.type);
168 SCJbSetUint(jb,
"icmp_code",
f->
icmp_s.code);
170 SCJbSetUint(jb,
"response_icmp_type",
f->
icmp_d.type);
171 SCJbSetUint(jb,
"response_icmp_code",
f->
icmp_d.code);
175 SCJbSetUint(jb,
"spi",
f->
esp.spi);
210 SCJbOpenObject(js,
"bypassed");
225 SCJbSetString(js,
"start", timebuf1);
228 static void EveExceptionPolicyLog(
SCJsonBuilder *js, uint16_t flag)
232 SCJbSetString(js,
"target",
234 SCJbSetString(js,
"policy",
241 SCJbSetString(js,
"target",
243 SCJbSetString(js,
"policy",
250 SCJbSetString(js,
"target",
252 SCJbSetString(js,
"policy",
262 SCJbSetString(js,
"policy",
271 SCJbSetString(js,
"policy",
278 SCJbSetString(js,
"target",
280 SCJbSetString(js,
"policy",
291 SCJbOpenObject(jb,
"flow");
296 SCJbSetString(jb,
"end", timebuf2);
299 SCJbSetUint(jb,
"age", age);
305 switch (flow_state) {
319 #ifdef CAPTURE_OFFLOAD
320 case FLOW_STATE_CAPTURE_BYPASSED:
327 SCLogDebug(
"invalid flow state: %d, contact developers", flow_state);
330 const char *reason = NULL;
332 reason =
"tcp_reuse";
342 SCJbSetString(jb,
"reason", reason);
350 SCJbOpenArray(jb,
"elephant_direction");
352 SCJbAppendString(jb,
"toserver");
354 SCJbAppendString(jb,
"toclient");
367 SCJbOpenArray(jb,
"exception_policy");
375 SCJbSetUint(jb,
"tx_cnt", tx_id);
385 if (
f->
proto == IPPROTO_TCP) {
386 SCJbOpenObject(jb,
"tcp");
391 snprintf(hexflags,
sizeof(hexflags),
"%02x",
393 SCJbSetString(jb,
"tcp_flags", hexflags);
395 snprintf(hexflags,
sizeof(hexflags),
"%02x",
397 SCJbSetString(jb,
"tcp_flags_ts", hexflags);
399 snprintf(hexflags,
sizeof(hexflags),
"%02x",
401 SCJbSetString(jb,
"tcp_flags_tc", hexflags);
407 if (tcp_state != NULL)
408 SCJbSetString(jb,
"state", tcp_state);
436 MemBufferReset(thread->
buffer);
443 EveFlowLogJSON(thread, jb,
f);
struct SCJsonBuilder SCJsonBuilder
void CreateIsoTimeString(const SCTime_t ts, char *str, size_t size)
void EveAddFlow(Flow *f, SCJsonBuilder *js)
OutputJsonCommonSettings cfg
void * SCFlowGetStorageById(const Flow *f, SCFlowStorageId id)
#define FLOW_IS_ELEPHANT_TOCLIENT
void EveAddAppProto(Flow *f, SCJsonBuilder *js)
TmEcode JsonLogThreadInit(ThreadVars *t, const void *initdata, void **data)
const char * PrintInetIPv6(const void *src, char *dst, socklen_t size, bool compress_ipv6)
struct Flow_::@126::@133 esp
const char * AppProtoToString(AppProto alproto)
Maps the ALPROTO_*, to its normalized string equivalent.
#define EXCEPTION_TARGET_FLAG_APPLAYER_ERROR
LiveDevice * LiveDeviceGetById(const int id)
bool SCProtoNameValid(uint16_t proto)
Function to check if the received protocol number is valid and do we have corresponding name entry fo...
void EveTcpFlags(const uint8_t flags, SCJsonBuilder *js)
jsonify tcp flags field Only add 'true' fields in an attempt to keep things reasonably compact.
const char * known_proto[256]
void OutputJsonBuilderBuffer(ThreadVars *tv, const Packet *p, Flow *f, SCJsonBuilder *js, OutputJsonThreadCtx *ctx)
void CreateEveFlowId(SCJsonBuilder *js, const Flow *f)
SCFlowStorageId GetFlowBypassInfoID(void)
const char * ExceptionPolicyTargetFlagToString(uint8_t target_flag)
void JsonFlowLogRegister(void)
struct Flow_::@128::@134 icmp_d
OutputInitResult OutputJsonLogInitSub(SCConfNode *conf, OutputCtx *parent_ctx)
void OutputRegisterFlowSubModule(LoggerId id, const char *parent_name, const char *name, const char *conf_name, OutputInitSubFunc InitFunc, FlowLogger FlowLogFunc, ThreadInitFunc ThreadInit, ThreadDeinitFunc ThreadDeinit)
Register a flow output sub-module.
@ FLOW_STATE_LOCAL_BYPASSED
#define EXCEPTION_TARGET_FLAG_DEFRAG_MEMCAP
enum ExceptionPolicy ExceptionPolicyTargetPolicy(uint8_t target_flag)
#define JB_SET_STRING(jb, key, val)
void EveAddCommonOptions(const OutputJsonCommonSettings *cfg, const Packet *p, const Flow *f, SCJsonBuilder *js, enum SCOutputJsonLogDirection dir)
Per thread variable structure.
const char * PrintInet(int af, const void *src, char *dst, socklen_t size)
#define FLOW_WRONG_THREAD
#define JB_SET_TRUE(jb, key)
#define FLOW_END_FLAG_TCPREUSE
#define FLOW_END_FLAG_EMERGENCY
#define STREAMTCP_STREAM_FLAG_HAS_GAP
#define EXCEPTION_TARGET_FLAG_REASSEMBLY_MEMCAP
#define EXCEPTION_TARGET_FLAG_MIDSTREAM
struct Flow_::@126::@132 icmp_s
uint8_t applied_exception_policy
#define EXCEPTION_TARGET_FLAG_SESSION_MEMCAP
#define FLOW_ACTION_ACCEPT
const char * ExceptionPolicyEnumToString(enum ExceptionPolicy policy, bool is_json)
union FlowAddress_::@125 address
#define FLOW_END_FLAG_SHUTDOWN
#define EXCEPTION_TARGET_FLAG_FLOW_MEMCAP
const char * StreamTcpStateAsString(const enum TcpState state)
uint16_t vlan_id[VLAN_MAX_LAYERS]
int FlowHasAlerts(const Flow *f)
Check if flow has alerts.
#define FLOW_END_FLAG_TIMEOUT
TmEcode JsonLogThreadDeinit(ThreadVars *t, void *data)
AppProto alproto
application level protocol
#define FLOW_END_FLAG_FORCED
#define FLOW_DIR_REVERSED
uint64_t AppLayerParserGetTxCnt(const Flow *f, void *alstate)
#define DEBUG_VALIDATE_BUG_ON(exp)
#define FLOW_IS_ELEPHANT_TOSERVER