Project

General

Profile

Actions

Optimization #4749

closed

app-layer: track changed txs for detect and logging

Added by Victor Julien almost 4 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Target version:
-
Effort:
Difficulty:
Label:

Description

When a parser runs it "knows" which txs have been created and/or updated. So it should communicate this to detect/output somehow so that these subsystems don't need to iterate all of them.


Related issues 2 (0 open2 closed)

Related to Suricata - Security #6299: mqtt: pcap with anomalies takes too long to process because of app-layer-event detectionClosedPhilippe AntoineActions
Related to Suricata - Optimization #7087: app-layer: track modified transactionsClosedPhilippe AntoineActions
Actions

Also available in: Atom PDF