doc: dhcp eve note for option 52 overload

Document that DHCP options carried in the overloaded BOOTP sname or
file fields are now merged into the EVE log option set alongside the
main options area.

Bug: #8538.
pull/15570/head
Samaresh Kumar Singh 4 months ago committed by Victor Julien
parent f06bb7d43e
commit af3abf100e

@ -3202,6 +3202,12 @@ The default DHCP logging level only logs enough information to map a
MAC address to an IP address. Enable extended mode to log all DHCP
message types in full detail.
When a DHCP message carries the Option Overload entry (option 52,
RFC 2132), the BOOTP ``sname`` and ``file`` header fields are used as
extra option storage. Suricata parses any options found in those
continuation areas alongside the standard options block, so values
carried in either area show up in the same EVE fields below.
Fields
~~~~~~

Loading…
Cancel
Save