Project

General

Profile

Actions

Optimization #4749

open

app-layer: track changed txs for detect and logging

Added by Victor Julien over 2 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

When a parser runs it "knows" which txs have been created and/or updated. So it should communicate this to detect/output somehow so that these subsystems don't need to iterate all of them.


Related issues 1 (0 open1 closed)

Related to Suricata - Security #6299: mqtt pcap with anomalies takes too long to process because of app-layer-event detectionClosedPhilippe AntoineActions
Actions #1

Updated by Philippe Antoine 5 months ago

  • Related to Security #6299: mqtt pcap with anomalies takes too long to process because of app-layer-event detection added
Actions

Also available in: Atom PDF