Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update ethernet/IP and CIP to account for new packet correlation ID #558

Closed
mmguero opened this issue Sep 9, 2024 · 1 comment
Closed
Assignees
Labels
enhancement New feature or request external Depends on a bug or feature external to this project ics Relating to ICS (Industrial Control Systems) devices logstash Relating to Malcolm's use of Logstash zeek Relating to Malcolm's use of Zeek
Milestone

Comments

@mmguero
Copy link
Collaborator

mmguero commented Sep 9, 2024

cisagov/icsnpp-enip#30 adds a "packet correlation ID" field to help correlate between enip and cip logs. This issue tracks the changes needed for Malcolm to do this.

@mmguero mmguero added the enhancement New feature or request label Sep 9, 2024
@mmguero mmguero self-assigned this Sep 9, 2024
@mmguero mmguero added external Depends on a bug or feature external to this project logstash Relating to Malcolm's use of Logstash zeek Relating to Malcolm's use of Zeek labels Sep 9, 2024
@mmguero mmguero added this to the v24.09.0 milestone Sep 9, 2024
@mmguero
Copy link
Collaborator Author

mmguero commented Sep 9, 2024

Done

Image

@mmguero mmguero closed this as completed Sep 9, 2024
@mmguero mmguero added the ics Relating to ICS (Industrial Control Systems) devices label Sep 9, 2024
This was referenced Sep 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request external Depends on a bug or feature external to this project ics Relating to ICS (Industrial Control Systems) devices logstash Relating to Malcolm's use of Logstash zeek Relating to Malcolm's use of Zeek
Projects
Status: Released
Development

No branches or pull requests

1 participant