Repository navigation
Add Suricata/Zeek EVE JSON parser (IDS alerts) - #34
Conversation
New EveParser in ax-normalize. EVE is NDJSON with each event tagged by an event_type and timestamp, and the interesting fields one level down in a per-type object. Generic NDJSON would stringify those nested objects; this parser flattens them into dotted columns (alert.category, alert.severity, dns.rrname, ...) so a field like alert.category is its own column — exactly what dist.chi2 --baseline reads as alert-type drift (quiet vs incident window), with a brand-new alert class surfacing as a category never seen in the baseline. Arrays are kept as canonical JSON (not exploded); scalars typed via json_to_value. Detected by the event_type (string) + timestamp signature and registered before NDJSON so an EVE stream claims itself before the generic NDJSON shape. Claims no extension (EVE is generically eve.json, owned by the JSON parser). Non-object / non-JSON lines are a clean Parse error. Mutation gate: 0 surviving mutants on the new file. The extensions() -> empty-slice mutant is a documented equivalent (same as Zeek/Journal). Closes #10 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Warning Review limit reached
More reviews will be available in 17 minutes and 49 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (4)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Implements the EVE JSON IDS-alert plugin — issue #10.
What
EVE is NDJSON with each event tagged by an
event_type(alert/dns/flow/…)and a
timestamp, and the interesting fields one level down in a per-type object.Generic NDJSON would stringify those nested objects;
EveParserflattens theminto dotted columns (
alert.category,alert.severity,dns.rrname, …) so afield like
alert.categoryis its own column — exactly whatdist.chi2 --baselinereads as alert-type drift (quiet vs incident window), with abrand-new alert class surfacing as a category never seen in the baseline.
Arrays are kept as canonical JSON (not exploded); scalars are typed via
json_to_value(EVE is well-typed JSON, so no string coercion needed).Routing
event_type(string) +timestampsignature, registeredbefore NDJSON so an EVE stream claims itself first.
eve.json(owned by the JSONparser); pipe it on stdin for EVE-aware flattening.
Errors
Non-JSON and valid-JSON-but-not-an-object lines are clean
AxError::Parse.Gates
fmt/clippy -D warnings/ full workspace tests green (both feature sets).eve.rs. Theextensions()→empty-slice mutant is a documented equivalent (same as Zeek/Journal).
eve; analert.categorymix shift between aquiet baseline and an incident window is flagged by
dist.chi2(exit 1).Closes #10
🤖 Generated with Claude Code