Actions
Bug #3346
closedBPF filter on command line not honored for pcap file
Affected Versions:
Effort:
Difficulty:
Label:
Needs backport
Description
A regression has been introduced in Suricata 4.1.0 (through 5.0). The BPF filter is not honored in pcap file mode if it is put on the command line.
For example, in the following command the filter is completely ignored:
suricata -r myfile.pcap port 22
Actions