- Registered on: 10/30/2017
- Last connection: 05/14/2018
- 02:31 PM Suricata Bug #2493: EngineAnalysisRules2 File Output Cannot Be Adjusted
- I think Jacob's solution is better than mine, although I'm not sure why there is a profiling config section and the c...
- 03:51 PM Suricata Bug #2493: EngineAnalysisRules2 File Output Cannot Be Adjusted
- Related MR: https://github.com/OISF/suricata/pull/3346
This method seems to still be in development, and per docum...
- 02:52 PM Suricata Bug #2493 (New): EngineAnalysisRules2 File Output Cannot Be Adjusted
- Putting this as a bug since as rule reloads occur, the file will continue to grow without bounds or limits.
- 02:45 PM Suricata Bug #1694: unix-socket reading 0 size pcap
- Related to other work I'm doing around hardening unix socket pcaps, so assigning to myself.
- 02:19 PM Suricata Bug #2465: Eve Stats will not be reported unless stats.log is enabled
- This might just be a documentation thing that using stats type for eve requires enabled. It looks like if filename is...
- 02:17 PM Suricata Bug #2465 (New): Eve Stats will not be reported unless stats.log is enabled
- If stats section enabled is set to no, adding stats type to eve alert configuration will not cause stats to be emitte...
- 03:10 AM Suricata Revision 697a5a19: pcap/file: fix missing files stopping engine #2451
When a missing (or empty named) file is passed to source-pcap-...
- 07:38 AM Suricata Revision 4b897c90: source-pcap-file: Directory mode may miss files (bug #2394)
Certain parameters of delay and poll interval could cause newl...
- 09:37 AM Suricata Bug #2451 (Closed): Missing Files Will Cause Pcap Thread to No Longer Run in Unix Socket Mode
- If a pcap file is sent to unix socket for processing that does not exist (e.g. slow i/o), the pcap thread is returnin...
- 06:41 AM Suricata Revision 790ef270: runmode-unix-socket: interrupt as commanded (2413)
Once interrupt occurs, reset the interrupt flag so that future...
Also available in: Atom