Project

General

Profile

Actions

Feature #8132

open

Add decompression support to pcap-file capture method

Added by A. Iooss about 23 hours ago. Updated about 16 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Target version:
Effort:
Difficulty:
Label:

Description

Suricata can produce pcap.xz files, but can only read uncompressed pcap files.
When dealing with large datasets of pcap, it can be useful to be able to load them directly in Suricata without having to decompress them beforehand.

Actions #1

Updated by Pierre Chifflier about 16 hours ago

Just adding a +1 on this
I'd be interested in both using this feature, and maybe volunteering to implement it :)

Actions

Also available in: Atom PDF