Project

General

Profile

Actions

Feature #5202

closed

eve/drop: include drop "reason"

Added by Victor Julien over 2 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

The eve drop facility logs dropped packets, optionally including the alert that triggered the drop. However if the engine drops for other reasons, e.g. the stream engine rejecting a packet, there is no indication of this.

This ticket proposes to add a reason field to the drop records that will give the user insight into where the drop originated.


Related issues 1 (1 open0 closed)

Related to Suricata - Task #4773: research: IPS behavior wrt resource limitsAssignedVictor JulienActions
Actions

Also available in: Atom PDF