Actions
Feature #4150
open
JL
CT
Profiling mode: Ticks used to generate an alert available?
Feature #4150:
Profiling mode: Ticks used to generate an alert available?
Effort:
medium
Difficulty:
low
Label:
Beginner
Description
StianB Nov 12th at 11:24 AM
When running Suricata in rule profiling mode, could we get the information about the number of ticks the rule used to create an Alert in the EVE? In a metadata field maybe?
4 replies
Andreas Herz 1 day ago
I'm not sure if I understand that correctly. You don't want the overall ticks but just those that were necessary for the alert trigger?
StianB 1 day ago
Yes, as an addition to the current rule-profiling output.
Andreas Herz 1 day ago
I see, I would recommend creating a redmine ticket for that feature request
Andreas Herz 1 day ago
Actions