Project

General

Profile

Actions

Bug #5374

open

pcap-log: breaking change in file names

Added by Jason Ish 4 months ago. Updated 4 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

With conditional logging now merged, the output filenames when reading from a pcap are now 0 indexed instead of time indexed, whether or not conditional logging is used.

Ideally there should be no change here as I think the old behaviour is preferable. If this is not possible, a reason for the change and upgrade documentation should be provided.


Related issues 1 (0 open1 closed)

Related to Feature #120: Capture full session on alertClosedScott JordanActions
Actions #1

Updated by Jason Ish 4 months ago

  • Related to Feature #120: Capture full session on alert added
Actions #2

Updated by Eric Leblond 4 months ago

If I remember correctly the 0 is just there for the initial file in pcap reading mode. In live mode, I think it is correct but let me check this.

Actions #3

Updated by Jason Ish 4 months ago

Eric Leblond wrote in #note-2:

If I remember correctly the 0 is just there for the initial file in pcap reading mode. In live mode, I think it is correct but let me check this.

Correct, in live mode its OK. However, in 6.0.x, even in pcap mode the file gets a timestamp based on the input packets.

Actions

Also available in: Atom PDF