Project

General

Profile

Actions

Optimization #5643

open

pcap: rule based conditional pcap logging

Added by Jason Ish about 2 years ago. Updated about 2 years ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Allow conditional pcap logging to be configured at the rule level, something like:

config:logging disable, type pcap, scope flow;

Use case: Some rules are more informational than actionable and might not make sense to trigger pcap logging, and in some cases conditional pcap logging may even be too much.


Related issues 1 (1 open0 closed)

Related to Suricata - Bug #7391: detect/config: 'scope' can't be applied to 'flow'NewOISF DevActions
Actions

Also available in: Atom PDF