Actions
Feature #7894
openoutput: log http2.window when needed
Effort:
Difficulty:
Label:
Description
Some keywords like http2.window
do not have a log field to match.
A rule using http2.window: >100;
will not have in the alert the precise value seen on the wire.
There is also tcp.wscale
and other keywords see https://github.com/OISF/suricata/pull/13816
Updated by Philippe Antoine 12 days ago
- Related to Task #6644: tracking: detect: integer as first-class support added
Actions