Project

General

Profile

Actions

Bug #6633

closed

stats: flows with a detection-only alproto not accounted in this protocol

Added by Philippe Antoine 5 months ago. Updated 4 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Subtasks 1 (0 open1 closed)

Bug #6636: stats: flows with a detection-only alproto not accounted in this protocol (7.0.x backport)ClosedPhilippe AntoineActions

Related issues 1 (0 open1 closed)

Related to Suricata - Bug #5769: Incomplete values for .stats."app_layer".flow.protoClosedPhilippe AntoineActions
Actions #1

Updated by Philippe Antoine 5 months ago

  • Related to Bug #5769: Incomplete values for .stats."app_layer".flow.proto added
Actions #2

Updated by Philippe Antoine 5 months ago

jq 'select(.event_type=="flow" and .app_proto=="enip") | .app_proto' log/eve.json | wc -l gives 1 ENIP detection-only flow

But
jq 'select(.event_type=="stats") | .stats."app_layer".flow.enip' log/eve.json gives 0

Actions #3

Updated by Philippe Antoine 5 months ago

  • Status changed from New to In Review
Actions #4

Updated by Victor Julien 4 months ago

  • Label Needs backport to 7.0 added
Actions #5

Updated by OISF Ticketbot 4 months ago

  • Subtask #6636 added
Actions #6

Updated by OISF Ticketbot 4 months ago

  • Label deleted (Needs backport to 7.0)
Actions #7

Updated by Philippe Antoine 4 months ago

  • Status changed from In Review to Resolved
Actions #8

Updated by Philippe Antoine 4 months ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF