Project

General

Profile

Actions

Bug #5374

closed
JI JI

pcap-log: breaking change in file names

Bug #5374: pcap-log: breaking change in file names

Added by Jason Ish almost 4 years ago. Updated about 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

With conditional logging now merged, the output filenames when reading from a pcap are now 0 indexed instead of time indexed, whether or not conditional logging is used.

Ideally there should be no change here as I think the old behaviour is preferable. If this is not possible, a reason for the change and upgrade documentation should be provided.


Related issues 1 (0 open1 closed)

Related to Suricata - Feature #120: Capture full session on alertClosedScott JordanActions

JI Updated by Jason Ish almost 4 years ago Actions #1

  • Related to Feature #120: Capture full session on alert added

EL Updated by Eric Leblond almost 4 years ago Actions #2

If I remember correctly the 0 is just there for the initial file in pcap reading mode. In live mode, I think it is correct but let me check this.

JI Updated by Jason Ish almost 4 years ago Actions #3

Eric Leblond wrote in #note-2:

If I remember correctly the 0 is just there for the initial file in pcap reading mode. In live mode, I think it is correct but let me check this.

Correct, in live mode its OK. However, in 6.0.x, even in pcap mode the file gets a timestamp based on the input packets.

VJ Updated by Victor Julien over 3 years ago Actions #4

  • Target version changed from 7.0.0-beta1 to 7.0.0-rc1

VJ Updated by Victor Julien over 3 years ago Actions #5

  • Priority changed from Normal to High

JI Updated by Jason Ish over 3 years ago Actions #6

  • Assignee changed from OISF Dev to Jason Ish

VJ Updated by Victor Julien over 3 years ago Actions #7

  • Status changed from New to Assigned

JI Updated by Jason Ish over 3 years ago Actions #8

  • Status changed from Assigned to In Review

VJ Updated by Victor Julien about 3 years ago Actions #9

  • Status changed from In Review to Closed
  • Priority changed from High to Normal
Actions

Also available in: PDF Atom