Project

General

Profile

Actions

Bug #6633

closed
PA PA

stats: flows with a detection-only alproto not accounted in this protocol

Bug #6633: stats: flows with a detection-only alproto not accounted in this protocol

Added by Philippe Antoine over 2 years ago. Updated over 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Subtasks 1 (0 open1 closed)

Bug #6636: stats: flows with a detection-only alproto not accounted in this protocol (7.0.x backport)ClosedPhilippe AntoineActions

Related issues 2 (0 open2 closed)

Related to Suricata - Bug #5769: Incomplete values for .stats."app_layer".flow.protoClosedPhilippe AntoineActions
Related to Suricata - Bug #7238: app-layer: protocol flows are miscounted in case of errorClosedShivani BhardwajActions

PA Updated by Philippe Antoine over 2 years ago Actions #1

  • Related to Bug #5769: Incomplete values for .stats."app_layer".flow.proto added

PA Updated by Philippe Antoine over 2 years ago Actions #2

jq 'select(.event_type=="flow" and .app_proto=="enip") | .app_proto' log/eve.json | wc -l gives 1 ENIP detection-only flow

But
jq 'select(.event_type=="stats") | .stats."app_layer".flow.enip' log/eve.json gives 0

PA Updated by Philippe Antoine over 2 years ago Actions #3

  • Status changed from New to In Review

VJ Updated by Victor Julien over 2 years ago Actions #4

  • Label Needs backport to 7.0 added

OT Updated by OISF Ticketbot over 2 years ago Actions #5

  • Subtask #6636 added

OT Updated by OISF Ticketbot over 2 years ago Actions #6

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine over 2 years ago Actions #7

  • Status changed from In Review to Resolved

PA Updated by Philippe Antoine over 2 years ago Actions #8

  • Status changed from Resolved to Closed

SB Updated by Shivani Bhardwaj over 1 year ago Actions #9

  • Related to Bug #7238: app-layer: protocol flows are miscounted in case of error added
Actions

Also available in: PDF Atom