Skip to content

Add Suricata/Zeek EVE JSON parser (IDS alerts) - #34

Merged
copyleftdev merged 1 commit into
mainfrom
feat/eve
May 31, 2026
Merged

copyleftdev merged 1 commit into
mainfrom
feat/eve

Conversation

@copyleftdev

Copy link
Copy Markdown
Owner

Implements the EVE JSON IDS-alert plugin — issue #10.

What

EVE is NDJSON with each event tagged by an event_type (alert/dns/flow/…)
and a timestamp, and the interesting fields one level down in a per-type object.
Generic NDJSON would stringify those nested objects; EveParser flattens them
into dotted columns
(alert.category, alert.severity, dns.rrname, …) so a
field like alert.category is its own column — exactly what dist.chi2 --baseline reads as alert-type drift (quiet vs incident window), with a
brand-new alert class surfacing as a category never seen in the baseline.

Arrays are kept as canonical JSON (not exploded); scalars are typed via
json_to_value (EVE is well-typed JSON, so no string coercion needed).

Routing

  • Detected by the event_type (string) + timestamp signature, registered
    before NDJSON so an EVE stream claims itself first.
  • Claims no extension — EVE is generically eve.json (owned by the JSON
    parser); pipe it on stdin for EVE-aware flattening.

Errors

Non-JSON and valid-JSON-but-not-an-object lines are clean AxError::Parse.

Gates

  • fmt / clippy -D warnings / full workspace tests green (both feature sets).
  • Mutation gate: 0 surviving mutants on eve.rs. The extensions() →
    empty-slice mutant is a documented equivalent (same as Zeek/Journal).
  • Smoke: an EVE stream sniffs as eve; an alert.category mix shift between a
    quiet baseline and an incident window is flagged by dist.chi2 (exit 1).

Closes #10

🤖 Generated with Claude Code

New EveParser in ax-normalize. EVE is NDJSON with each event tagged by an
event_type and timestamp, and the interesting fields one level down in a
per-type object. Generic NDJSON would stringify those nested objects; this
parser flattens them into dotted columns (alert.category, alert.severity,
dns.rrname, ...) so a field like alert.category is its own column — exactly what
dist.chi2 --baseline reads as alert-type drift (quiet vs incident window), with
a brand-new alert class surfacing as a category never seen in the baseline.
Arrays are kept as canonical JSON (not exploded); scalars typed via json_to_value.

Detected by the event_type (string) + timestamp signature and registered before
NDJSON so an EVE stream claims itself before the generic NDJSON shape. Claims no
extension (EVE is generically eve.json, owned by the JSON parser). Non-object /
non-JSON lines are a clean Parse error.

Mutation gate: 0 surviving mutants on the new file. The extensions() ->
empty-slice mutant is a documented equivalent (same as Zeek/Journal).

Closes #10

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 31, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@copyleftdev, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 17 minutes and 49 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 837019c8-2472-4d2f-a22d-1cbe5960015e

📥 Commits

Reviewing files that changed from the base of the PR and between fc32926 and 966d08c.

📒 Files selected for processing (4)
  • .cargo/mutants.toml
  • crates/ax-normalize/src/parser.rs
  • crates/ax-normalize/src/parsers/eve.rs
  • crates/ax-normalize/src/parsers/mod.rs
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/eve

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@copyleftdev
copyleftdev merged commit 56747bb into main May 31, 2026
2 checks passed
@copyleftdev
copyleftdev deleted the feat/eve branch May 31, 2026 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a Suricata/Zeek EVE JSON parser (IDS alerts)

1 participant