General

Profile

Danny Browning

  • Registered on: 10/30/2017
  • Last connection: 05/14/2018

Issues

Projects

Activity

05/14/2018

02:31 PM Suricata Bug #2493: EngineAnalysisRules2 File Output Cannot Be Adjusted
I think Jacob's solution is better than mine, although I'm not sure why there is a profiling config section and the c...

04/19/2018

03:51 PM Suricata Bug #2493: EngineAnalysisRules2 File Output Cannot Be Adjusted
Related MR: https://github.com/OISF/suricata/pull/3346
This method seems to still be in development, and per docum...
02:52 PM Suricata Bug #2493 (New): EngineAnalysisRules2 File Output Cannot Be Adjusted
Putting this as a bug since as rule reloads occur, the file will continue to grow without bounds or limits.
Engine...

04/10/2018

02:45 PM Suricata Bug #1694: unix-socket reading 0 size pcap
Related to other work I'm doing around hardening unix socket pcaps, so assigning to myself.

03/23/2018

02:19 PM Suricata Bug #2465: Eve Stats will not be reported unless stats.log is enabled
This might just be a documentation thing that using stats type for eve requires enabled. It looks like if filename is...
02:17 PM Suricata Bug #2465 (New): Eve Stats will not be reported unless stats.log is enabled
If stats section enabled is set to no, adding stats type to eve alert configuration will not cause stats to be emitte...

03/21/2018

03:10 AM Suricata Revision 697a5a19: pcap/file: fix missing files stopping engine #2451
https://redmine.openinfosecfoundation.org/issues/2451
When a missing (or empty named) file is passed to source-pcap-...

03/01/2018

07:38 AM Suricata Revision 4b897c90: source-pcap-file: Directory mode may miss files (bug #2394)
https://redmine.openinfosecfoundation.org/issues/2394
Certain parameters of delay and poll interval could cause newl...

02/27/2018

09:37 AM Suricata Bug #2451 (Closed): Missing Files Will Cause Pcap Thread to No Longer Run in Unix Socket Mode
If a pcap file is sent to unix socket for processing that does not exist (e.g. slow i/o), the pcap thread is returnin...

01/23/2018

06:41 AM Suricata Revision 790ef270: runmode-unix-socket: interrupt as commanded (2413)
https://redmine.openinfosecfoundation.org/issues/2413
Once interrupt occurs, reset the interrupt flag so that future...

Also available in: Atom