Project

General

Profile

Actions

Optimization #4207

closed
PA JF

Bug #4941: alerts: 5.0.8/6.0.4 count noalert sigs towards built-in alert limit

Use configurable or more dynamic @ PACKET_ALERT_MAX@

Optimization #4207: Use configurable or more dynamic @ PACKET_ALERT_MAX@

Added by Philippe Antoine over 5 years ago. Updated over 3 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Currently, PACKET_ALERT_MAX is hardcoded to 15

This turned out to be a problem writing S-V test, with many signatures (different variations of a feature) matching on the same packet
That was HTTP keywords on HTTP2 traffic, where I had one packet containing 3 requests

It would be nice to have this value be configurable from suricata.yaml


Subtasks 1 (0 open1 closed)

Optimization #5178: detect/alert: improve packet alert queue handlingRejectedJuliana Fajardini ReichowActions

Related issues 2 (0 open2 closed)

Copied to Suricata - Optimization #5121: Use configurable or more dynamic @ PACKET_ALERT_MAX@ (5.0.x backport)ClosedJuliana Fajardini ReichowActions
Copied to Suricata - Optimization #5125: Use configurable or more dynamic @ PACKET_ALERT_MAX@ (6.0.x backport)ClosedJuliana Fajardini ReichowActions

VJ Updated by Victor Julien over 5 years ago Actions #1

  • Assignee set to OISF Dev
  • Target version changed from TBD to 7.0.0-beta1

VJ Updated by Victor Julien almost 5 years ago Actions #2

  • Assignee changed from OISF Dev to Juliana Fajardini Reichow

JF Updated by Juliana Fajardini Reichow almost 5 years ago Actions #3

  • Status changed from New to In Progress

VJ Updated by Victor Julien about 4 years ago Actions #4

  • Priority changed from Normal to High
  • Parent task set to #4941

JF Updated by Juliana Fajardini Reichow about 4 years ago Actions #5

  • Status changed from In Progress to In Review

JL Updated by Jeff Lucovsky about 4 years ago Actions #6

  • Copied to Optimization #5121: Use configurable or more dynamic @ PACKET_ALERT_MAX@ (5.0.x backport) added

JL Updated by Jeff Lucovsky about 4 years ago Actions #7

  • Copied to Optimization #5125: Use configurable or more dynamic @ PACKET_ALERT_MAX@ (6.0.x backport) added

JF Updated by Juliana Fajardini Reichow over 3 years ago Actions #9

  • Status changed from In Review to Closed
Actions

Also available in: PDF Atom