Actions
Bug #5120
closed
JL
JF
alerts: 5.0.8/6.0.4 count noalert sigs towards built-in alert limit (6.0.x backport)
Bug #5120:
alerts: 5.0.8/6.0.4 count noalert sigs towards built-in alert limit (6.0.x backport)
Description
Changes in alerting in 5.0.8/6.0.4 store noalert sigs in the packet alert array before removing them when finalizing the alerts. This solved several issues (#4663, #4670), however it introduces a new issue.
When many noalert rules are used, for example for flowbit "setter" logic, these rules now consume space in the alert array, leaving less space for "real" alerts that should be outputted. Since there is a built-in limit of 15 (see #4207) its not hard to reach this limit.
JL Updated by Jeff Lucovsky about 4 years ago
- Copied from Bug #4941: alerts: 5.0.8/6.0.4 count noalert sigs towards built-in alert limit added
VJ Updated by Victor Julien almost 4 years ago
- Target version changed from 6.0.5 to 6.0.6
VJ Updated by Victor Julien almost 4 years ago
- Status changed from Assigned to Closed
- Assignee changed from Shivani Bhardwaj to Juliana Fajardini Reichow
VJ Updated by Victor Julien almost 4 years ago
- Subject changed from alerts: 5.0.8/6.0.4 count noalert sigs towards built-in alert limit to alerts: 5.0.8/6.0.4 count noalert sigs towards built-in alert limit (6.0.x backport)
Actions