Project

General

Profile

Actions

Feature #1245

open

Add "drop-only" and "alert-only" option for pcap-log

Added by Andreas Herz about 7 years ago. Updated over 2 years ago.

Status:
New
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

It would be nice to have the pcap files for matching rules instead of the whole traffic passed.

What i want to have ist, that i have a rule that was matched to be logged into fast.log and when i want to analyse it i can just use the suitable pcap file.
It would be also ok to have several matched rules gathered into one pcap file.
But i want to prevent insanely huge pcap files with 99% valid traffic wasting the HDD space.

Is this a valid feature request? And if you think it's not too hard to implement can you point me where i could start to write a patch.

Actions #1

Updated by Victor Julien about 7 years ago

  • Assignee set to Anonymous
  • Priority changed from High to Normal
  • Target version changed from 2.0.3 to TBD
Actions #2

Updated by Victor Julien about 7 years ago

Sure, it'd be a welcome contribution.

Actions #3

Updated by Andreas Herz over 2 years ago

  • Assignee set to Community Ticket
Actions

Also available in: Atom PDF