You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
suricata/doc/userguide/output
Richard McConnell 94c8be22d4 output/tls: Allow logging of cl-handshake params
Ticket: 6695

Add new custom log fields:

"client_handshake" which logs the following:
1. TLS version used during handshake
2. TLS extensions, excluding GREASE, SNI and ALPN
3. All cipher suites, excluding GREASE
4. All signature algorithms, excluding GREASE

The use-case is for logging TLS handshake parameters in order to survey
them, and so that JA4 hashes can be computed offline (in the case that
they're not already computed for the purposes of rule matching).
1 year ago
..
eve output/tls: Allow logging of cl-handshake params 1 year ago
files-json/elk
custom-http-logging.rst http-log: deprecate 2 years ago
custom-tls-logging.rst tls-log: deprecate 2 years ago
index.rst
log-rotation.rst doc: removed unified2 output 7 years ago
lua-output.rst doc/userguide: upgrade notes for Lua 2 years ago
syslog-alerting-comp.rst doc/userguide: spelling 3 years ago