General

Profile

Andreas Herz

Issues

open closed Total
Assigned issues 12 45 57
Reported issues 31 39 70

Projects

Project Roles Registered on
Suricata Developer, OISF Team, OISF Manager 12/02/2015
Suricata-Update Developer, OISF Team, OISF Manager 10/31/2017

Activity

06/03/2020

07:50 PM Suricata Documentation #3748 (New): Add documentation for flags keyword
The flags keyword is not yet documented, we also need to check if it works the same like in snort (I expect that). Andreas Herz

06/01/2020

07:48 PM Suricata Support #3737: Suricata Installation
This depends on your setup, I recommend reading our documentation: https://suricata.readthedocs.io/en/latest/
The OS...
Andreas Herz

05/26/2020

08:24 PM Suricata Support #3706: Suricata don't detect threats to other IP other than his own
I don't know if Virtualbox offers such a functionality but at least from the dump it's rather clear that the traffic ... Andreas Herz

05/22/2020

09:10 PM Suricata Support #3722: configure suricata.yaml for performance
That depends on your environment/setup. There are guidelines at the official documentation: https://suricata.readthed... Andreas Herz

05/19/2020

08:08 PM Suricata Support #3706: Suricata don't detect threats to other IP other than his own
Did you ensure that the routing/mirroring of the traffic is forwarded to that interface?
If you run *tcpdump -nn -vv...
Andreas Herz
10:08 AM Suricata Support #3706 (Feedback): Suricata don't detect threats to other IP other than his own
Hi,
please stop setting Support Tickets to Immediate priority. Also please provide more details about your setup a...
Andreas Herz

05/18/2020

08:37 PM Suricata Support #3704: Suricata alerts don't show up in Prelude-SIEM
Can you share more details about your setup/configuration? Andreas Herz

05/12/2020

08:45 PM Suricata Support #2725: stream/packet on wrong thread
Peter Manev wrote in #note-124:
> wrt 1 - I dont understand this " very minor numbers (like 10 of 1000000 packets) ...
Andreas Herz
09:57 AM Suricata Support #2725: stream/packet on wrong thread
So what I can tell from looking at the stats from around 100 machines:
1. It's still an issue when 2 interfaces ar...
Andreas Herz

05/08/2020

07:17 PM Suricata Bug #3617: Missing icmp netflow
I can confirm that with 5.0.3 and your pcap. Although I don't even see type 13 in netflow, only 8 and 0. It's even le... Andreas Herz

Also available in: Atom