Actions
Feature #5202
closedeve/drop: include drop "reason"
Effort:
Difficulty:
Label:
Description
The eve drop facility logs dropped packets, optionally including the alert that triggered the drop. However if the engine drops for other reasons, e.g. the stream engine rejecting a packet, there is no indication of this.
This ticket proposes to add a reason
field to the drop records that will give the user insight into where the drop originated.
Updated by Victor Julien over 2 years ago
- Related to Task #4773: research: IPS behavior wrt resource limits added
Updated by Victor Julien over 2 years ago
- Status changed from Assigned to In Progress
Updated by Victor Julien over 2 years ago
- Status changed from In Progress to Closed
Actions