Actions
Feature #3316
openUnix socket: support dumping flow table
Effort:
Difficulty:
Label:
Description
Idea is to use the unix socket interface dump the flow table. This could be used to analyse the internal state of flows.
The conntrack tool from Linux/Netfilter could be an example.
Updated by Victor Julien about 5 years ago
- Related to Task #3288: Suricon 2019 brainstorm added
Updated by Victor Julien about 5 years ago
- Related to Feature #3295: Unix socket: support to receive flow shunting information added
Updated by Victor Julien about 5 years ago
Suggestions about use cases and things like syntax and such are welcome.
Updated by Danny Browning about 5 years ago
One thing as we were exploring saving flow state is that there is not currently a stable identifier for flows between suricata runs. If we plan to load the dumped flow table, flow hash_id will need to be stable (no seed), or support for community flow id will need to be added to flow as a way to marry dumped state and captured flows.
Updated by Victor Julien about 4 years ago
- Related to Task #3301: Research: Failover support within the current IPS implementation added
Actions