For the issuer field, the kv split fails with an error:
message:field [suricata.eve.tls.issuerdn] does not contain value_split [=]
The field_split for the subject kv processor is a good start, and just needs to begin with a , to properly trim the comma from extracted values. The issuer kv processor's field_split needs to be updated to use the same pattern as the subject kv processor.
The Suricata integation doesn't handle extra commas in fields of a distinguished name (subject or issuer).
For the subject field, the kv split happens successfully, but leaves a trailing comma:
For the issuer field, the kv split fails with an error:
The field_split for the subject kv processor is a good start, and just needs to begin with a
,
to properly trim the comma from extracted values. The issuer kv processor's field_split needs to be updated to use the same pattern as the subject kv processor.