Actions
Support #6301
closedpcap capture
Description
Hi, when I search the information how can I only save data captured (captured it to pcap files) which match with alerts (rule) in suricata, but I can find any idea of this one. So, I wanna know how can i save only data captured which match with alerts in suricata and how it work, thanks
Updated by Philippe Antoine 23 days ago
- Status changed from New to Closed
Please use https://forum.suricata.io for support questions such as this
You may want to see conditional pcap logging referenced in https://docs.suricata.io/en/latest/configuration/suricata-yaml.html
Actions