Actions
Feature #7894
openoutput: log http2.window when needed
Effort:
Difficulty:
Label:
Description
Some keywords like http2.window
do not have a log field to match.
A rule using http2.window: >100;
will not have in the alert the precise value seen on the wire.
There is also tcp.wscale
and other keywords see https://github.com/OISF/suricata/pull/13816
No data to display
Actions