Edward Fjellskål

  • Email:
  • Registered on: 11/29/2010
  • Last connection: 10/27/2012

Activity

Reported issues: 8

11/03/2011

05:46 AM Suricata Feature #294: Limit inspection of a stream and/or rule...
From the initial conversation with Victor J on IRC, I was talking about a packet counter and a byte counter, both for...

10/12/2011

06:27 AM Suricata Bug #342 (Closed): Errors compiling with --disable-gccmarch-native
...

06/30/2011

02:18 AM Suricata Feature #294 (New): Limit inspection of a stream and/or rule...
I would like to have different rule options to limit inspection of a streams.
Not sure if it would speed up or slo...

01/17/2011

02:55 AM Suricata Bug #271 (Closed): Need for proper option for testing a setup
When distributing a set of binary,configuration files and rules, it is convenient to have a way to test the setup bef...

12/30/2010

09:44 AM Suricata Bug #267: Problem with [ipvars] in icmp rule
ohhh... crapz.... sårry with a big O...
For some reason, my interface reverted to not the one that I really use, s...
05:32 AM Suricata Bug #267 (Rejected): Problem with [ipvars] in icmp rule
Trying out:
alert icmp $HOME_NET any -> [8.8.4.4,8.8.8.8] any (msg:"IDS is alive - ping google-dns test signature";...

12/28/2010

12:09 AM Suricata Bug #264 (Closed): No payload for http alert data.
The http_* keywords use the http state which is working on top of the stream engine.
It currently works on ACK'd dat...

12/08/2010

09:59 AM Suricata Feature #251 (Assigned): More stats in stats.log
1) I would like to see "drop rates"!
2) I would like to see syn and syn/ack counts...

11/30/2010

12:49 AM Suricata Feature #249 (New): Configure host-os-policy from a file, like snorts host_attribute.xml
To be able to automate the configuration of frag and stream policy,
I propose that it is possible to read such info ...

11/29/2010

12:36 AM Suricata Feature #247 (Closed): Config option to set stats.log update interval
In src/counters.h SC_PERF_MGMTT_TTS is hardcoded to 8 sec.
This makes the stats.log file large fast, and I dont need...

Also available in: Atom