mirror of https://github.com/OISF/suricata
dcerpc/log: Log fields particular to an RPC version
Log fields that only are meant to be in a PDU for a particular RPC version. Since DCERPC/UDP works on RPC version 4 and DCERPC/TCP works on RPC version 5, there are certain fields that are particular to each version. Remove call_id from the logger for UDP. Add activityuuid and seqnum fields to the logger for UDP. call_id and (activityuuid + seqnum) fields are used to uniquely pair a request with response for RPC versions 5 and 4 respectively.pull/5570/head
parent
2033f386f9
commit
269324e84d
Loading…
Reference in New Issue