Actions
Feature #8132
openAdd decompression support to pcap-file capture method
Effort:
Difficulty:
Label:
Description
Suricata can produce pcap.xz files, but can only read uncompressed pcap files.
When dealing with large datasets of pcap, it can be useful to be able to load them directly in Suricata without having to decompress them beforehand.
Updated by Pierre Chifflier about 17 hours ago
Just adding a +1 on this
I'd be interested in both using this feature, and maybe volunteering to implement it :)
Actions