Bug #339
browse event at relying node
Start date:
Due date:
% Done:
0%
Resolution:
fixed
Description
Hi,
I've configure Prelude IDS with relaying support and I'm having some problems on accessing the event at the relayed node, for instance I generate an event on node1, with prewikka I can access to that information, but when I try to access at the relayed node it throws this error (see attach).
I'm defining the field in prelude-correlator like this:
ctx:set("alert.correlation_alert.alertident(>>).alertident", INPUT:getraw("alert.messageid"))
Any help would be appreciated.
--
Rui
History
#1 Updated by over 15 years ago
It was marked as spam so the attach doesn't work and inline too. So I put it on a web page: http://estudass.es/~rpvilao/error.html
#2 Updated by Yoann VANDOORSELAERE over 15 years ago
- Status changed from New to Closed
- Resolution set to fixed
(In r11103) Invalid variable name, fix #339.
#3 Updated by Yoann VANDOORSELAERE almost 15 years ago
- Project changed from PRELUDE SIEM to Prewikka
- Category deleted (
generic) - Target version deleted (
80)
#4 Updated by Yoann VANDOORSELAERE almost 15 years ago
- Target version set to 0.9.15