Project

General

Profile

Actions

Feature #6164

closed

Task #5645: tracking: elephant flow detection

rules: allow matching on flow pkts and bytes

Added by Philippe Antoine over 1 year ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Related issues 3 (2 open1 closed)

Related to Suricata - Task #4772: tracking: parity between fields logged and fields available for detectionAssignedVictor JulienActions
Related to Suricata - Feature #294: Limit inspection of a stream and/or rule...ClosedCommunity TicketActions
Related to Suricata - Feature #5646: rules: allow matching on flow pkts and bytes in either directionIn ReviewShivani BhardwajActions
Actions #1

Updated by Philippe Antoine over 1 year ago

  • Related to Task #4772: tracking: parity between fields logged and fields available for detection added
Actions #2

Updated by Philippe Antoine over 1 year ago

  • Status changed from New to In Review
Actions #3

Updated by Philippe Antoine over 1 year ago

  • Subject changed from detect: new keyword flow.pkts_toclient to detect: new keyword flow.pkts_toclient to server and bytes as well
Actions #4

Updated by Philippe Antoine over 1 year ago

  • Related to Feature #294: Limit inspection of a stream and/or rule... added
Actions #5

Updated by Philippe Antoine about 1 year ago

  • Related to Feature #5646: rules: allow matching on flow pkts and bytes in either direction added
Actions #6

Updated by Philippe Antoine about 1 year ago

  • Status changed from In Review to Closed
Actions #7

Updated by Shivani Bhardwaj 4 months ago

  • Parent task set to #5645
Actions #8

Updated by Shivani Bhardwaj 4 months ago

  • Subject changed from detect: new keyword flow.pkts_toclient to server and bytes as well to rules: allow matching on flow pkts and bytes
Actions #9

Updated by Philippe Antoine 4 months ago

This is not a subtask of elephant flow detection in #5645
This exists also on its own ;-)

Actions #10

Updated by Shivani Bhardwaj 4 months ago

Philippe Antoine wrote in #note-9:

This is not a subtask of elephant flow detection in #5645
This exists also on its own ;-)

ah ok. I changed it because its duplicate (#5646) was marked a subtask of #5645. Please change as seems fit to you.

Actions #11

Updated by Philippe Antoine 4 months ago

Ok for me, no big deal

Actions

Also available in: Atom PDF