Task #7026
openapp-protos: trigger raw stream inspection
Description
For application layer protocols over TCP that have transactions, we need to trigger stream inspection once they have at least one full message parseable, to avoid missing alerts that happen early on in the stream (as seen with #7004).
Updated by Juliana Fajardini Reichow about 1 year ago
Enip: should wait for https://github.com/OISF/suricata/pull/10901 to be merged.
Updated by Juliana Fajardini Reichow about 1 year ago
ENIP merged: https://github.com/OISF/suricata/pull/11184
Updated by Shivani Bhardwaj 3 months ago
I think this ticket should be rejected with an update in the title as this just reflects what shall be done to fix the bug stated in #7004. Thoughts?
Updated by Victor Julien 3 months ago
Updated by Shivani Bhardwaj 3 months ago
Victor Julien wrote in #note-15:
Not sure, implementing this affects more than tx logging.
I see. Thank you. I shall find that out then and see if the title needs improvement.
Updated by Shivani Bhardwaj 23 days ago
Merged batch \#1: https://github.com/OISF/suricata/pull/13237
Updated by Shivani Bhardwaj 21 days ago
Merged batch \#2: https://github.com/OISF/suricata/pull/13282
Updated by Shivani Bhardwaj 3 days ago
- Status changed from In Progress to Resolved
Closed by: https://github.com/OISF/suricata/pull/13389