Project

General

Profile

Actions

Feature #6164

closed
PA PA

Task #5645: tracking: elephant flow detection

rules: allow matching on flow pkts and bytes

Feature #6164: rules: allow matching on flow pkts and bytes

Added by Philippe Antoine almost 3 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Related issues 3 (1 open2 closed)

Related to Suricata - Task #4772: tracking: parity between fields logged and fields available for detectionAssignedVictor JulienActions
Related to Suricata - Feature #294: Limit inspection of a stream and/or rule...ClosedCommunity TicketActions
Related to Suricata - Feature #5646: rules: allow matching on flow pkts and bytes in either directionClosedShivani BhardwajActions

PA Updated by Philippe Antoine almost 3 years ago Actions #1

  • Related to Task #4772: tracking: parity between fields logged and fields available for detection added

PA Updated by Philippe Antoine almost 3 years ago Actions #2

  • Status changed from New to In Review

PA Updated by Philippe Antoine almost 3 years ago Actions #3

  • Subject changed from detect: new keyword flow.pkts_toclient to detect: new keyword flow.pkts_toclient to server and bytes as well

PA Updated by Philippe Antoine over 2 years ago Actions #4

  • Related to Feature #294: Limit inspection of a stream and/or rule... added

PA Updated by Philippe Antoine over 2 years ago Actions #5

  • Related to Feature #5646: rules: allow matching on flow pkts and bytes in either direction added

PA Updated by Philippe Antoine over 2 years ago Actions #6

  • Status changed from In Review to Closed

SB Updated by Shivani Bhardwaj over 1 year ago Actions #7

  • Parent task set to #5645

SB Updated by Shivani Bhardwaj over 1 year ago Actions #8

  • Subject changed from detect: new keyword flow.pkts_toclient to server and bytes as well to rules: allow matching on flow pkts and bytes

PA Updated by Philippe Antoine over 1 year ago Actions #9

This is not a subtask of elephant flow detection in #5645
This exists also on its own ;-)

SB Updated by Shivani Bhardwaj over 1 year ago Actions #10

Philippe Antoine wrote in #note-9:

This is not a subtask of elephant flow detection in #5645
This exists also on its own ;-)

ah ok. I changed it because its duplicate (#5646) was marked a subtask of #5645. Please change as seems fit to you.

PA Updated by Philippe Antoine over 1 year ago Actions #11

Ok for me, no big deal

Actions

Also available in: PDF Atom