Project

General

Profile

Optimization #4207

Use configurable or more dynamic @ PACKET_ALERT_MAX@

Added by Philippe Antoine 7 months ago. Updated about 1 month ago.

Status:
In Progress
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Currently, PACKET_ALERT_MAX is hardcoded to 15

This turned out to be a problem writing S-V test, with many signatures (different variations of a feature) matching on the same packet
That was HTTP keywords on HTTP2 traffic, where I had one packet containing 3 requests

It would be nice to have this value be configurable from suricata.yaml

#1

Updated by Victor Julien 7 months ago

  • Assignee set to OISF Dev
  • Target version changed from TBD to 7.0rc1
#2

Updated by Victor Julien about 2 months ago

  • Assignee changed from OISF Dev to Juliana Fajardini Reichow
#3

Updated by Juliana Fajardini Reichow about 1 month ago

  • Status changed from New to In Progress

Also available in: Atom PDF