Project

General

Profile

Actions

Feature #793

closed

Suricata.log + exit stats - add % dropped

Added by Peter Manev about 11 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
-
Effort:
Difficulty:
Label:

Description

...
[31878] 2/4/2013 -- 03:17:20 - (source-pfring.c:477) <Info> (ReceivePfringThreadExitStats) -- (RxPFReth37) Kernel: Packets 6573157847, dropped 12447441
[31878] 2/4/2013 -- 03:17:20 - (source-pfring.c:478) <Info> (ReceivePfringThreadExitStats) -- (RxPFReth37) Packets 2278190551, bytes 5916311319139
[31878] 2/4/2013 -- 03:17:20 - (stream-tcp.c:4178) <Info> (StreamTcpExitPrintStats) -- Stream TCP processed 1804326931 TCP packets
[31878] 2/4/2013 -- 03:17:20 - (alert-fastlog.c:321) <Info> (AlertFastLogExitPrintStats) -- Fast log output wrote 460027 alerts
[31878] 2/4/2013 -- 03:17:20 - (log-httplog.c:617) <Info> (LogHttpLogExitPrintStats) -- HTTP logger logged 393118 requests
...

It would be handy if a "% dropped" could be added at the end of each "dropped" line for each thread for both pfring and afpacket.
Makes it easier/faster to read/troubleshoot/tune on high traffic.
ex:

[31878] 2/4/2013 -- 03:17:20 - (source-pfring.c:477) <Info> (ReceivePfringThreadExitStats) -- (RxPFReth37) Kernel: Packets 6573157847, dropped 12447441 - %0.189 dropped

Actions #1

Updated by Victor Julien over 10 years ago

  • Target version set to TBD
Actions #2

Updated by Andreas Herz over 8 years ago

  • Assignee set to OISF Dev
Actions #3

Updated by Peter Manev over 8 years ago

  • Status changed from New to Closed

Done.

Actions #4

Updated by Victor Julien over 6 years ago

  • Target version deleted (TBD)
Actions

Also available in: Atom PDF