userguide: add JA3S fields to the TLS logger documentation

pull/3874/head
Mats Klepsland 6 years ago
parent a4eaef25d6
commit 800608ab65

@ -492,6 +492,7 @@ If extended logging is enabled the following fields are also included:
* "not_before": The NotBefore field from the TLS certificate
* "not_after": The NotAfter field from the TLS certificate
* "ja3": The JA3 fingerprint consisting of both a JA3 hash and a JA3 string
* "ja3s": The JA3S fingerprint consisting of both a JA3 hash and a JA3 string
JA3 must be enabled in the Suricata config file (set 'app-layer.protocols.tls.ja3-fingerprints' to 'yes').

@ -209,7 +209,7 @@ YAML::
extended: yes # enable this for extended logging information
# custom allows to control which tls fields that are included
# in eve-log
#custom: [subject, issuer, serial, fingerprint, sni, version, not_before, not_after, certificate, chain, ja3]
#custom: [subject, issuer, serial, fingerprint, sni, version, not_before, not_after, certificate, chain, ja3, ja3s]
The default is to log certificate subject and issuer. If ``extended`` is
enabled, then the log gets more verbose.

Loading…
Cancel
Save