jasonish / py-idstools

idstools: Snort and Suricata Rule and Event Utilities in Python (Including a Rule Update Tool)
277 stars 85 forks source link

u2json event.appid output is in byte format and mangled #85

Open csbflyer opened 3 years ago

csbflyer commented 3 years ago

u2json is outputting the event.appid field as a byte string and is missing data.

For example: b'\x00un RPC\x00Static\x00ntrol\x00ssion service\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'

Version 0.6.4