Project

General

Profile

Actions

Bug #8962

open
SD SD

erf/file: ERF PAD and META type records and extension headers are not supported

Bug #8962: erf/file: ERF PAD and META type records and extension headers are not supported

Added by Stephen Donnelly about 12 hours ago.

Status:
Assigned
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The ERF format defines PAD and META type records which may exist in packet trace files and can/should be skipped by Suricata. The presence of these record types currently stops Suricata reading the input file.

The ERF format defines extension headers. The presence of ERF extension headers prevents Suricata from reading the input file.

Both of these ERF features are supported by source-erf-dag for live capture but not source-erf-file for file input.

No data to display

Actions

Also available in: PDF Atom