Actions
Feature #1879
closedeve: optionally add 'flow' record to alerts
Effort:
Difficulty:
Label:
Description
Add flow record to alerts. Mostly thinking about flow's startts as this would help FPC retrieval. It may also be interesting for an analyst to know if the flow is small or big wrt number of packets and bytes.
Flow records will be incomplete, as they are not yet considered done if a packet is still referring to them.
Actions