PiRogueToolSuite / deb-packages

PiRogue Debian packages
https://pts-project.org/
GNU General Public License v3.0
2 stars 2 forks source link

Add Suricata Rule 'sid' to Dashboard #22

Open arky opened 3 weeks ago

arky commented 3 weeks ago

Please kindly add Suricata rule 'sid' 'alert' message to Suricata Section of the Dashboard

Background Context

During the documentation review, it was discovered that the current design of Suricata section doesn't provide enough information to allow users to search source Suricata rules.

Purpose

The user would like to investigate the Suricata rule which generated the alert.

Workflow

  1. User selects a alert from the Suricata section of the dashboard.
  2. Next, the user copies the 'sid' or the alert 'msg' to clipboard.
  3. User then opens the suriata.rules and search the file content using the sid or msg as search phrase.
  4. User narrows down to the right Suricata rule that generated the message.