Project

General

Profile

Actions

Feature #384

closed

Add support for logging alert packets in libpcap format

Added by David Wharton over 12 years ago. Updated almost 12 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

This is a feature request to add support to be able to log packets that trigger an alert in libpcap format. This should also include logging of packets that occur as the result of 'tag' directives.

Actions #1

Updated by Victor Julien over 12 years ago

We're trying to limit the outputs Suricata has itself and offload to Barnyard2 if feasible. I think barnyard2 does well at producing the output you seek.

Actions #2

Updated by Victor Julien almost 12 years ago

  • Status changed from New to Closed
  • Priority changed from High to Normal
Actions

Also available in: Atom PDF