Project

General

Profile

Actions

Task #5465

open

doc/userguide: document terminating behavior of rule actions

Added by Victor Julien 4 months ago. Updated about 1 month ago.

Status:
Assigned
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

Various actions have different "terminating behaviors" in different scenarios.

e.g.:
alert will not terminate, but is limited to a max number of alerts per packet in the output
pass will immediately stop logging more alerts for the same packet and future alerts in the flow
drop will currently log all alerts for a packet, then drop the rest of the flow

Actions #1

Updated by Victor Julien 4 months ago

Once we have fully documented the current behavior we need to consider if the behavior actually makes sense. If changes are needed we can track that in a new ticket.

Actions #2

Updated by Victor Julien 2 months ago

  • Target version changed from 7.0.0-beta1 to 7.0.0-rc1
Actions #3

Updated by Victor Julien about 1 month ago

  • Target version changed from 7.0.0-rc1 to 7.0.0
Actions

Also available in: Atom PDF