Project

General

Profile

Actions

Support #1796

closed

PCAP_CNT value does not match Frame Number on TSHARK or Wireshark

Added by Xavier Lassoie about 9 years ago. Updated about 9 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:

Description

When using Suricata offline using 'suricata -r log.pcap --runmode autofp -l logs/' and then searching an alert with Tshark (tshark -r log.pcap -V -Y "frame.number==46887") or Wireshark using the value of pcap_cnt in eve-alert.json file, we see that the packet is not matching the alert.

This is Suricata version 3.0 RELEASE

Actions

Also available in: Atom PDF