# Unable to find list of taggable events

**URL:** <https://forum.suricata.io/t/unable-to-find-list-of-taggable-events/6013>\
**Category:** Rules\
**Created:** [September 12, 2025, 8:10am UTC](https://forum.suricata.io/t/unable-to-find-list-of-taggable-events/6013 "2025-09-12T08:10:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbarnett](https://avatars.discourse-cdn.com/v4/letter/b/6bbea6/32.png) [@bbarnett](https://forum.suricata.io/u/bbarnett)\
**Post date:** [September 12, 2025, 8:10am UTC](https://forum.suricata.io/t/unable-to-find-list-of-taggable-events/6013/1 "2025-09-12T08:10:38Z")

</div>

Looking for some info which I cannot seem to find. Any pointers to where I can find it, would be quite helpful.

I see the following rules in ssh-events.rules:

```auto
alert ssh any any -> any any (msg:"SURICATA SSH invalid banner"; flow:established; app-layer-event:ssh.invalid_banner; classtype:protocol-command-decode; sid:2228000; rev:1;)
alert ssh any any -> any any (msg:"SURICATA SSH too long banner"; flow:established; app-layer-event:ssh.long_banner; classtype:protocol-command-decode; sid:2228001; rev:1;)
alert ssh any any -> any any (msg:"SURICATA SSH invalid record"; flow:established; app-layer-event:ssh.invalid_record; classtype:protocol-command-decode; sid:2228002; rev:1;)

```

I’ve searched the documentation, and cannot find what options are available for protocols, or the SSH protocol anywhere. I’ve searched the source on github for invalid\_banner, searched google, and using ‘stings’ on the binary does provide a hit:

```auto
# strings /usr/bin/suricata | grep invalid_banner
incomplete_datainvalid_datainvalid_banner
invalid_bannerlong_bannerinvalid_recordlong_kex_recordsrc/quic/frames.rs

```

I am unsure why searching on github produces zero results.

However, all I want is a list of every single possible match I can use. I see long\_banner, invalid\_record, invalid\_banner, what other matches may I use? It’s unclear to me if the above three examples are all the possibilities.

Thanks

---

<div class="post-metadata">

**Author:** ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)\
**Post date:** [September 12, 2025, 8:39am UTC](https://forum.suricata.io/t/unable-to-find-list-of-taggable-events/6013/2 "2025-09-12T08:39:28Z")

</div>

The various `*-events.rules` are intended to give a complete set of rules for all available events.

The internal representation can have a slightly different notation:

```auto
git grep -i -E "invalid_*banner"
rules/ssh-events.rules:alert ssh any any -> any any (msg:"SURICATA SSH invalid banner"; flow:established; app-layer-event:ssh.invalid_banner; classtype:protocol-command-decode; sid:2228000; rev:1;)
rust/src/ssh/ssh.rs: InvalidBanner,
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidBanner);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidBanner);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidBanner);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidBanner);

```

Then grepping for `SSHEvent` is easy:

```auto
git grep SSHEvent
rust/src/ssh/ssh.rs:pub enum SSHEvent {
rust/src/ssh/ssh.rs: fn set_event(&mut self, event: SSHEvent) {
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::LongKexRecord);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidRecord);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidRecord);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidBanner);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidBanner);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::LongBanner);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::LongBanner);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidBanner);
rust/src/ssh/ssh.rs: self.set_event(SSHEvent::InvalidBanner);
rust/src/ssh/ssh.rs: get_eventinfo: Some(SSHEvent::get_event_info),
rust/src/ssh/ssh.rs: get_eventinfo_byid: Some(SSHEvent::get_event_info_by_id),

```

Or check `ssh.rs`

```auto
#[derive(AppLayerEvent)]
pub enum SSHEvent {
    InvalidBanner,
    LongBanner,
    InvalidRecord,
    LongKexRecord,
}

```

---

<div class="post-metadata">

**Author:** ![bbarnett](https://avatars.discourse-cdn.com/v4/letter/b/6bbea6/32.png) [@bbarnett](https://forum.suricata.io/u/bbarnett)\
**Post date:** [September 17, 2025, 3:30pm UTC](https://forum.suricata.io/t/unable-to-find-list-of-taggable-events/6013/3 "2025-09-17T15:30:15Z")

</div>

OK. Thanks, appreciate the FYI
