On Thu, May 10, 2012 at 8:50 AM, David Mashburn <[email protected]> wrote: > I have been working on some custom decoders, and as part of that work I > extracted data of interest into the available decoded fields. Beyond the > ability to use the decoded fields in a related rule, is there any other use > for the decoded fields? Is there an advantage to matching on a decoded field > versus just using <match> tags to search for particular text strings? I > guess that you could create a multi-condition rule across several decoded > fields, but I'm not sure that my needs call for that level of complexity. >
I don't know of any specific benefit, other than what you describe. > A related observation for decoded fields is that it appears that only a > subset of the decoded fields are stored if you use a database for logging > alerts. The alert table has only src_ip, dst_ip, src,_prt, and dst_port > columns, so I'm again wondering if there is really a value to using any of > the other decoded fields for rules processing if you aren't capturing that in > the associated record. Certainly one could extend the schema and then go > back and include that data in the insert operation, which might make using > that data repository for more useful for reporting on fields beyond those > already captured. My intent was to use iReport or something similar to > develop reports that queried data from the db. > > Anyone else use the db for reporting or have a similar use case for the > additional decoded fields? > > David Mashburn > IT Security Manager > U.S. Pharmacopeia > >
