Actions
Feature #4840
openstats: distinguish between observational stats and performance stats
Description
Stats are currently a mix of observations, like packet counts or flow counts and stats meant to give insights into how suricata is doing internally. Best example of the latter is the flow.mgr.* set of stats. To avoid confusion we may want to somehow split this or at least make it clearer that these are different classes of info.
As an example: the flow.tcp and flow.udp count the number of tcp flows and udp flows, but comparing these with flow.mgr.flows_checked makes little sense, as the latter is just an indication of how busy the flow manager is keeping itself. A flow may be checked multiple times by the flow manager.
Updated by Philippe Antoine over 1 year ago
- Assignee set to OISF Dev
- Target version set to TBD
Updated by Juliana Fajardini Reichow 17 days ago
- Related to Task #8123: Suricon 2025 Brainstorm added
Updated by Juliana Fajardini Reichow 17 days ago
Was brought up during one Q&A session, about the exception policy stats, actually.
Actions