Bug #7884
open
exceptions: handle logging for per-packet policies
Added by Juliana Fajardini Reichow 4 months ago.
Updated 29 days ago.
Description
When implementing #6215 the implications of flow.memcap and defrag.memcap affecting only packets weren't taken into consideration.
This means that Suricata is able to generate stats for when these are triggered, but can't actually log the triggered policy with a flow, as there isn't one associated when we apply the policies.
Wonder if we should make this a new subtype of the anomaly type
- anomaly:
enabled: yes
types:
# decode: no
# stream: no
# applayer: yes
exception-policy: yes
#packethdr: no
- Target version changed from 8.0.2 to 9.0.0-beta1
- Label deleted (
Needs backport to 7.0)
- Status changed from New to Assigned
- Label Needs backport to 8.0 added
- Label deleted (
Needs backport to 8.0)
Also available in: Atom
PDF