|
|
|
|
@ -5,7 +5,6 @@ In your Suricata.yaml, find the tls-log section and edit as follows:
|
|
|
|
|
|
|
|
|
|
::
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
- tls-log:
|
|
|
|
|
enabled: yes # Log TLS connections.
|
|
|
|
|
filename: tls.log # File to store TLS logs.
|
|
|
|
|
@ -19,10 +18,6 @@ And in your tls.log file you would get the following, for example:
|
|
|
|
|
|
|
|
|
|
12/03/16-19:20:14.85859 10.10.10.4:58274 -> 192.0.78.24:443 VERSION='TLS 1.2' suricata-ids.org NOTBEFORE='2016-10-27T20:36:00' NOTAFTER='2017-01-25T20:36:00'
|
|
|
|
|
|
|
|
|
|
::
|
|
|
|
|
12/03/16-19:20:20.36849 10.10.10.4:39472 -> 192.30.253.113:443 VERSION='TLS 1.2' github.com NOTBEFORE='2016-03-10T00:00:00' NOTAFTER='2018-05-17T12:00:00'
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The list of supported format strings is the following:
|
|
|
|
|
|
|
|
|
|
* %n - client SNI
|
|
|
|
|
|