Actions
Feature #5646
openTask #5645: tracking: elephant flow detection
rules: allow matching on flow pkts and bytes
Description
Probably need some logic to express direction, e.g.
flow.pkts:toserver,>,10000; flow.pkts:either,=,10000; flow.bytes:both,>,1G;
Exact syntax TBD.
Updated by Philippe Antoine 6 months ago
- Related to Feature #6164: detect: new keyword flow.pkts_toclient to server and bytes as well added
Updated by Philippe Antoine 5 months ago
@Victor Julien is there more to do here after https://redmine.openinfosecfoundation.org/issues/6164 ?
Maybe the sum of both directions ?
Actions