# 3.0RC1 11/25/2015 * Feature #1116: ips packet stats in stats.log * Feature #1137: Support IP lists in threshold.config * Bug #1150: TLS store disabled by TLS EVE logging * Bug #1210: global counters in stats.log * Feature #1228: Suricata stats.log in JSON format * Feature #1265: Replace response on Suricata dns decoder when dns error please * Optimization #1269: Convert SM List from linked list to array * Feature #1281: long snort ruleset support for "SC_ERR_NOT_SUPPORTED(225): content length greater than 255 unsupported" * Feature #1282: support for base64_decode from snort's ruleset * Feature #1342: Support Cisco erspan traffic * Feature #1374: Write pre-aggregated counters for all threads * Feature #1408: multi tenancy for detection * Bug #1423: Unix domain log file writer should automatically reconnect if receiving program is restarted. * Feature #1440: Load rules file from a folder or with a star pattern rather then adding them manually to suricata.yaml * Feature #1454: Proposal to add Lumberjack/CEE formatting option to EVE JSON syslog output for compatibility with rsyslog parsing * Bug #1466: Rule reload - Rules won't reload if rule files are listed in an included file. * Bug #1467: Specifying an IPv6 entry before an IPv4 entry in host-os-policy causes ASAN heap-buffer-overflow. * Bug #1472: Should 'goodsigs' be 'goodtotal' when checking if signatures were loaded in detect.c? * Bug #1475: app-layer-modbus: AddressSanitizer error (heap-buffer-overflow) * Bug #1481: Leading whitespace in flowbits variable names * Bug #1482: suricata 2.1 beta4: StoreStateTxFileOnly crashes * Bug #1485: hostbits - leading and trailing spaces are treated as part of the name and direction. * Bug #1488: stream_size <= and >= modifiers function as < and > (equality is not functional) * Bug #1491: pf_ring is not able to capture packets when running under non-root account * Feature #1492: Add HUP coverage to output json-log * Bug #1493: config test (-T) doesn't fail on missing files * Bug #1494: off by one on rulefile count * Feature #1498: color output * Feature #1499: json output for engine messages * Bug #1500: suricata.log * Feature #1502: Expose tls fields to lua * Bug #1508: address var parsing issue * Feature #1514: SSH softwareversion regex should allow colon * Bug #1517: Order dependent, ambiguous YAML in multi-detect. * Bug #1518: multitenancy - selector vlan - vlan id range * Bug #1521: multitenancy - global vlan tracking relation to selector * Bug #1523: Decoded base64 payload short by 16 characters * Feature #1527: Add ability to compile as a Position-Independent Executable (PIE) * Bug #1530: multitenant mapping relation * Bug #1531: multitenancy - confusing tenant id and vlan id output * Bug #1556: MTU setting on NIC interface not considered by af-packet * Bug #1557: stream: retransmission not detected * Bug #1565: defrag: evasion issue * Feature #1568: TLS lua output support * Feature #1569: SSH lua support * Feature #1582: Redis output support * Feature #1586: Add flow memcap counter * Bug #1597: dns parser issue (master) * Feature #1599: rule profiling: json output * Bug #1601: tls: server name logging