You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc/userguide
Jason Ish 029fd1be59 eve: add rule generation source to alert record
When an alert is generated from firewall context, add an engine value of
"fw", otherwise "td" (for threat detect).

The engine field is only added when firewall mode is enabled.

Ticket: #8456
4 months ago
..
3rd-party-integration doc/userguide: new 3rd party section, add bluecoat 8 years ago
_static doc/userguide: avoid horizontal scroll on rtd 3 years ago
appendix doc: adjust for master to main rename 1 year ago
capture-hardware doc: move more rules to dedicated css container 5 months ago
configuration doc: move more rules to dedicated css container 5 months ago
devguide doc: document flow life cycle callback API 4 months ago
file-extraction doc: minor verbiage tweaks and reST fix 11 months ago
firewall doc/userguide: add note on rule reloads 5 months ago
install doc/userguide: update windivert instructions 9 months ago
ips src: doc: remove double-space typos 8 months ago
licenses doc: convert fancy quotes to straight quotes 7 years ago
lua ntp: expose logged fields to lua 4 months ago
manpages userguide/suricatactl: use suricata community page 2 years ago
output eve: add rule generation source to alert record 4 months ago
partials ntp: add transaction logging 5 months ago
performance hs: warn about the same cache directory 8 months ago
plugins doc/ndpi: move ndpi docs to new plugins section 1 year ago
protocols doc/userguide: add initial protocols overview 12 months ago
reputation doc: spelling 3 years ago
rule-management userguide: add references to rules/README to docs 6 months ago
rules detect/mqtt: reason_code keyword is now a multi-integer 4 months ago
upgrade doc: upgrade notes for changes to ike output 11 months ago
.gitignore doc/userguide: generate eve documentation 2 years ago
Makefile.am userguide/Makefile: don't add "install" to EXTRA_DIST 7 months ago
Makefile.sphinx
README.md devguide: move into userguide as last chapter 5 years ago
acknowledgements.rst doc: Add missing contributors to ack file 1 year ago
command-line-options.rst doc: Improve grammar, spelling and clarifications 6 years ago
conf.py doc: address config conversion note 4 months ago
convert.py doc/optimization: move "convert.py" to Python3 3 years ago
docutils.conf doc: add docutils.conf to disable smart quotes 3 years ago
generate-evedoc.sh doc/userguide: generate eve documentation 2 years ago
index.rst doc/userguide: add initial protocols overview 12 months ago
initscripts.rst doc: Improve grammar, spelling and clarifications 6 years ago
install.rst docs: use correct suricata version mentions 8 months ago
make-sense-alerts.rst doc: Improve grammar, spelling and clarifications 6 years ago
public-data-sets.rst doc: add more public datasets 7 months ago
quickstart.rst doc: move more rules to dedicated css container 5 months ago
requirements.txt docs: adjust readthedocs config to new options 3 years ago
security.rst doc: fix typo /var/run/suricata in file permissions docs. 12 months ago
support-status.rst devguide: make 'contributing' a chapter 3 years ago
unix-socket.rst doc: adjust for master to main rename 1 year ago
upgrade.rst stats: replace dashes by underscores in app-layer protocols 4 months ago
verifying-source-files.rst docs: use correct suricata version mentions 8 months ago
what-is-suricata.rst doc: Improve grammar, spelling and clarifications 6 years ago

README.md

Suricata User Guide

This directory contains the Suricata Guide. The Suricata Developer's guide is included as a chapter of the Guide. The Sphinx Document Generator is used to build the documentation. For a primer os reStructuredText see the reStructuredText Primer.

Verifying Changes

There are a number of output formats to choose from when making the source documentation locally (e.g. html, pdf, man).

The documentation source can be built with make -f Makefile.sphinx html. Substitute the 'html' word for desired output format.

There are different application dependencies based on the output desired.