Actions
Feature #1879
closed
VJ
EL
eve: optionally add 'flow' record to alerts
Feature #1879:
eve: optionally add 'flow' record to alerts
Effort:
Difficulty:
Label:
Description
Add flow record to alerts. Mostly thinking about flow's startts as this would help FPC retrieval. It may also be interesting for an analyst to know if the flow is small or big wrt number of packets and bytes.
Flow records will be incomplete, as they are not yet considered done if a packet is still referring to them.
Actions