Actions
Support #6301
closedpcap capture
Description
Hi, when I search the information how can I only save data captured (captured it to pcap files) which match with alerts (rule) in suricata, but I can find any idea of this one. So, I wanna know how can i save only data captured which match with alerts in suricata and how it work, thanks
Actions