Project

General

Profile

Actions

Feature #724

closed
FI DB

Prevent resetting in UNIX socket mode

Feature #724: Prevent resetting in UNIX socket mode

Added by Felix Ingram over 13 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Normal
Target version:
Effort:
Difficulty:
Label:

Description

The UNIX socket mode allows multiple pcaps to be submitted to the engine. At the moment the pcaps are processed in the order in which they are submitted and the engine is reset before each file is processed.

Any events that would have been triggered by a stream that spans separate files will therefore not be reported.

The new feature would prevent the resetting of the engine between pcaps and would produce results similar to what would have been generated if the pcaps had been merged and submitted to the engine as a single file.

The UNIX socket currently allows a log directory to be submitted with each file, so a design decision would have to be made as to which directory received the alert.


Related issues 2 (0 open2 closed)

Related to Suricata - Feature #2222: Batch submission of PCAPs over the socketClosedDanny BrowningActions
Has duplicate Suricata - Feature #1476: Suricata Unix socket PCAP processing stats should not need to reset after each runClosedDanny BrowningActions

VJ Updated by Victor Julien over 13 years ago Actions #1

  • Status changed from New to Assigned
  • Assignee set to Eric Leblond
  • Target version set to TBD

VJ Updated by Victor Julien over 8 years ago Actions #2

  • Assignee changed from Eric Leblond to Danny Browning
  • Target version changed from TBD to 70

DB Updated by Danny Browning over 8 years ago Actions #3

  • Is duplicate of Feature #2222: Batch submission of PCAPs over the socket added

DB Updated by Danny Browning over 8 years ago Actions #4

  • Status changed from Assigned to Closed

VJ Updated by Victor Julien over 8 years ago Actions #5

  • Is duplicate of deleted (Feature #2222: Batch submission of PCAPs over the socket)

VJ Updated by Victor Julien over 8 years ago Actions #6

  • Status changed from Closed to Assigned

VJ Updated by Victor Julien over 8 years ago Actions #7

  • Related to Feature #2222: Batch submission of PCAPs over the socket added

VJ Updated by Victor Julien over 8 years ago Actions #8

  • Has duplicate Feature #1476: Suricata Unix socket PCAP processing stats should not need to reset after each run added

VJ Updated by Victor Julien over 8 years ago Actions #9

  • Status changed from Assigned to Closed
  • Target version changed from 70 to 4.1beta1
Actions

Also available in: PDF Atom