Project

General

Profile

Support #3227

How to obtain Suricata Reassembled TCP UDP stream in the source code

Added by Berk Ulku 9 days ago. Updated 9 days ago.

Status:
New
Priority:
Normal
Target version:
Affected Versions:
Effort:
medium
Difficulty:
Label:

Description

Hello,
I want to obtain reassembled stream payload for both TCP and UDP in Suricata. How can i obtain stream data in source code? Which methods/classes in the source provide or manipulate stream data?
Shortly, I want to extract all streaming data from Suricata and use it, when it is sniffing the network.

I installed binary on my machine and for the time being I am trying to find a function or a class where I can dump reassembled stream payloads(both Tcp and Udp) in the C source code so that I can save the stream payload to a memory block instead of parsing EVE JSON or any other log file.

History

#1

Updated by Andreas Herz 9 days ago

  • Assignee set to Community Ticket
  • Target version set to Support

Also available in: Atom PDF