Project

General

Profile

Actions

Feature #473

open
VJ CT

pcap log: alert log with packet indexes

Feature #473: pcap log: alert log with packet indexes

Added by Victor Julien almost 14 years ago. Updated 5 months ago.

Status:
New
Priority:
Normal
Target version:
Effort:
medium
Difficulty:
medium
Label:

Description

A log similar to alert-pcapinfo that lists alerts for the pcap files we write out.

The pcap-log module keeps track of a per pcap file packet index, so when we get an alert, we can log the packet number the alert was generated for.

Should log: sid,gid,rev,5tuple,packet number.


Related issues 2 (2 open0 closed)

Related to Suricata - Task #7336: Suricon 2024 brainstormAssignedVictor JulienActions
Related to Suricata - Task #8123: Suricon 2025 BrainstormAssignedVictor JulienActions

JI Updated by Jason Ish almost 8 years ago Actions #1

  • Effort set to medium
  • Difficulty set to medium

AH Updated by Andreas Herz almost 7 years ago Actions #2

  • Assignee set to Community Ticket

PA Updated by Philippe Antoine over 2 years ago Actions #3

  • Status changed from New to Closed

We have pcap_cnt in eve.json alert events.

Feel free to reopen of there is more to do

VJ Updated by Victor Julien over 2 years ago Actions #4

  • Status changed from Closed to New

pcap_cnt is only about the packet index on the input side, not the output side

PA Updated by Philippe Antoine over 2 years ago Actions #5

So, is this when we do conditional pcap logging on an alert ?

VJ Updated by Victor Julien over 1 year ago Actions #6

  • Related to Task #7336: Suricon 2024 brainstorm added

JF Updated by Juliana Fajardini Reichow 5 months ago Actions #7

  • Related to Task #8123: Suricon 2025 Brainstorm added

JF Updated by Juliana Fajardini Reichow 5 months ago Actions #8

Discussed briefly on Brainstorm 2025: it's nice, but we would wait for someone from the community to take upon this one.

Actions

Also available in: PDF Atom