Actions
Support #1796
closedPCAP_CNT value does not match Frame Number on TSHARK or Wireshark
Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:
Description
When using Suricata offline using 'suricata -r log.pcap --runmode autofp -l logs/' and then searching an alert with Tshark (tshark -r log.pcap -V -Y "frame.number==46887") or Wireshark using the value of pcap_cnt in eve-alert.json file, we see that the packet is not matching the alert.
This is Suricata version 3.0 RELEASE
Actions