Project

General

Profile

Actions

Optimization #5643

open

pcap: rule based conditional pcap logging

Added by Jason Ish over 1 year ago. Updated over 1 year ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Allow conditional pcap logging to be configured at the rule level, something like:

config:logging disable, type pcap, scope flow;

Use case: Some rules are more informational than actionable and might not make sense to trigger pcap logging, and in some cases conditional pcap logging may even be too much.

Actions #1

Updated by Victor Julien over 1 year ago

  • Description updated (diff)
Actions

Also available in: Atom PDF