Fix snort rule with blank content & WR packet in alert 07/56307/1
authorEddie Arrage <eddie.arrage@huawei.com>
Tue, 24 Apr 2018 00:22:07 +0000 (00:22 +0000)
committerEddie Arrage <eddie.arrage@huawei.com>
Tue, 24 Apr 2018 00:29:26 +0000 (00:29 +0000)
commit841cc31ad8cc6a6a2e76488bde1f7103013671ae
tree8a7973d5bee56fbc4b1632efc4e89914f40e1c49
parent106c87ed8b51ee9e202cc831f8d22d3f0c8240a9
Fix snort rule with blank content & WR packet in alert

- Fix bug with addition of content field in rule definition
that causes rules with a blank content fields to inhibit
snort from starting successfully.
- Write more of the packet data for snort alert into Redis
- Above includes X-Real-IP, X-Forwarded-For header fields
for http traffic from proxy that shows source IP

Some packet data is missing in alerts from snort.

Change-Id: I2c5c29e514d1ca9e8e5b9b3f7990afa87c6311b9
Signed-off-by: Eddie Arrage <eddie.arrage@huawei.com>
samples/services/snort_ids/docker/grpc/snort_alerts.py
samples/services/snort_ids/docker/grpc/snort_server.py