Project

General

Profile

Actions

Feature #1879

closed

eve: optionally add 'flow' record to alerts

Added by Victor Julien over 7 years ago. Updated almost 7 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Add flow record to alerts. Mostly thinking about flow's startts as this would help FPC retrieval. It may also be interesting for an analyst to know if the flow is small or big wrt number of packets and bytes.

Flow records will be incomplete, as they are not yet considered done if a packet is still referring to them.

Actions

Also available in: Atom PDF