Project

General

Profile

Actions

Feature #4150

open

Profiling mode: Ticks used to generate an alert available?

Added by Jeff Lucovsky 10 months ago. Updated 10 months ago.

Status:
New
Priority:
Normal
Target version:
Effort:
medium
Difficulty:
low
Label:
Beginner

Description

StianB Nov 12th at 11:24 AM
When running Suricata in rule profiling mode, could we get the information about the number of ticks the rule used to create an Alert in the EVE? In a metadata field maybe?

4 replies

Andreas Herz 1 day ago
I'm not sure if I understand that correctly. You don't want the overall ticks but just those that were necessary for the alert trigger?

StianB 1 day ago
Yes, as an addition to the current rule-profiling output.

Andreas Herz 1 day ago
I see, I would recommend creating a redmine ticket for that feature request

Andreas Herz 1 day ago


Related issues

Related to Task #4097: Suricon 2020 brainstormNewVictor JulienActions
Actions #1

Updated by Jeff Lucovsky 10 months ago

  • Related to Task #4097: Suricon 2020 brainstorm added
Actions #2

Updated by Victor Julien 10 months ago

  • Assignee set to Community Ticket
  • Target version set to TBD
  • Effort set to medium
  • Difficulty set to low
  • Label Beginner added

I think this should be fairly trivial. At the end of the individual rule inspection we can know the ticks, so we should be able to store than in the PacketAlert struct and output it in EVE.

Actions

Also available in: Atom PDF