Project

General

Profile

Actions

Feature #7099

open

Addition of total bytes to the flow logs

Added by Peter Manev 3 months ago. Updated 3 months ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

We currently have to server,to client bytes in the flow logs.
It is very useful to have a total bytes filed that has the total for that flow in the flow log.
It makes it easier for aggregations and searches based on the event_type flow that Suricata has in a SIEM.

Actions #1

Updated by Philippe Antoine 3 months ago

Is not that for post processing tools ? (and not be too verbose with duplicate info)

Actions

Also available in: Atom PDF