Actions
Feature #7481
openrules/actions: explicit action scopes
Effort:
Difficulty:
Label:
Description
Allow setting the scope of the applied action (packet or flow currently) explicitly in the rule.
Suggesting a syntax:
(drop|pass)[:(packet|flow)] pass:flow tls any any -> any any (tls.sni; content:"suricata.io"; ... )
Actions